openPDC 和 openHistorian 中的组件加载机制将构造并运行任何指定的类型,而该类型可能是一个无效的待加载组件。具有已认证用户账户且能够在主机文件系统上放置文件的攻击者,可以利用此漏洞运行任意的构造函数代码,且该代码将以受影响服务账户的权限执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Grid Protection Alliance | openHistorian | < 2.8.580 |
affected |
< 2.8.585 |
affected | ||
2.8.585 |
unaffected | ||
| Grid Protection Alliance | openPDC | < 2.9.477 |
affected |
< 2.9.482 |
affected | ||
2.9.482 |
unaffected | ||
| Grid Protection Alliance | openPDC (Docker image) | < 2.9.477 |
affected |
< 2.9.482 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Grid Protection Alliance | openPDC | 0 ~ 2.9.477 | - |
|
| Grid Protection Alliance | openPDC (Docker image) | 0 ~ 2.9.477 | - |
|
| Grid Protection Alliance | openHistorian | 0 ~ 2.8.580 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100730 | 9.8 CRITICAL | Grid Protection Alliance openPDC and openHistorian Deserialization of Untrusted Data |
| CVE-2026-105278 | 9.8 CRITICAL | Grid Protection Alliance openPDC (Docker image) Use of Hard-coded Credentials |
| CVE-2026-105281 | 7.5 HIGH | Grid Protection Alliance openPDC and openHistorian Missing Authentication for Critical Fun |
| CVE-2026-85479 | 5.3 MEDIUM | Grid Protection Alliance openPDC and openHistorian Missing Authentication for Critical Fun |
| CVE-2026-101022 | 4.3 MEDIUM | Grid Protection Alliance openPDC and openHistorian Server-Side Request Forgery (SSRF) |
No comments yet