在默认配置下,openPDC 的内部数据发布服务器在不进行身份验证的情况下接受网络连接。未经授权的攻击者可以通过网络连接访问该接口,从而获取系统中完整的设备拓扑和测量拓扑信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Grid Protection Alliance | openPDC | 0 ~ 2.9.477 | - |
|
| Grid Protection Alliance | openPDC (Docker image) | 0 ~ 2.9.477 | - |
|
| Grid Protection Alliance | openHistorian | 0 ~ 2.8.580 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100730 | 9.8 CRITICAL | Grid Protection Alliance openPDC and openHistorian Deserialization of Untrusted Data |
| CVE-2026-105278 | 9.8 CRITICAL | Grid Protection Alliance openPDC (Docker image) Use of Hard-coded Credentials |
| CVE-2026-104629 | 8.8 HIGH | Grid Protection Alliance openPDC and openHistorian Use of Externally-Controlled Input to S |
| CVE-2026-85479 | 5.3 MEDIUM | Grid Protection Alliance openPDC and openHistorian Missing Authentication for Critical Fun |
| CVE-2026-101022 | 4.3 MEDIUM | Grid Protection Alliance openPDC and openHistorian Server-Side Request Forgery (SSRF) |
No comments yet