发布在 Docker 镜像中的 openPDC 包含一个固定的默认管理凭据,且首次使用时不强制用户更改。任何拥有网络访问权限的攻击者,若能接触到管理接口,便可以使用该凭据进行身份验证,从而获得应用程序的完全管理控制权。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Grid Protection Alliance | openPDC (Docker image) | < 2.9.477 |
affected |
< 2.9.482 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Grid Protection Alliance | openPDC (Docker image) | 0 ~ 2.9.477 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100730 | 9.8 CRITICAL | Grid Protection Alliance openPDC and openHistorian Deserialization of Untrusted Data |
| CVE-2026-104629 | 8.8 HIGH | Grid Protection Alliance openPDC and openHistorian Use of Externally-Controlled Input to S |
| CVE-2026-105281 | 7.5 HIGH | Grid Protection Alliance openPDC and openHistorian Missing Authentication for Critical Fun |
| CVE-2026-85479 | 5.3 MEDIUM | Grid Protection Alliance openPDC and openHistorian Missing Authentication for Critical Fun |
| CVE-2026-101022 | 4.3 MEDIUM | Grid Protection Alliance openPDC and openHistorian Server-Side Request Forgery (SSRF) |
No comments yet