openPDC 的 Modbus 连接功能接受调用方指定的目标地址和端口,且对可攻击的内部主机无任何限制。经过身份验证的用户可以尝试连接到内部网络中的任意目的地,从而暴露哪些目的地是可达的。通过重复尝试,攻击者有可能绘制内部网络的拓扑结构。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Grid Protection Alliance | openPDC | 0 ~ 2.9.477 | - |
|
| Grid Protection Alliance | openPDC (Docker image) | 0 ~ 2.9.477 | - |
|
| Grid Protection Alliance | openHistorian | 0 ~ 2.8.580 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100730 | 9.8 CRITICAL | Grid Protection Alliance openPDC and openHistorian Deserialization of Untrusted Data |
| CVE-2026-105278 | 9.8 CRITICAL | Grid Protection Alliance openPDC (Docker image) Use of Hard-coded Credentials |
| CVE-2026-104629 | 8.8 HIGH | Grid Protection Alliance openPDC and openHistorian Use of Externally-Controlled Input to S |
| CVE-2026-105281 | 7.5 HIGH | Grid Protection Alliance openPDC and openHistorian Missing Authentication for Critical Fun |
| CVE-2026-85479 | 5.3 MEDIUM | Grid Protection Alliance openPDC and openHistorian Missing Authentication for Critical Fun |
No comments yet