默认配置下,openPDC 上基于 STTP 的数据发布服务在未进行身份验证的情况下接受网络连接。未经验证的远程攻击者可以连接到此接口并与之交换数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Grid Protection Alliance | openPDC | 0 ~ 2.9.477 | - |
|
| Grid Protection Alliance | openPDC (Docker image) | 0 ~ 2.9.477 | - |
|
| Grid Protection Alliance | openHistorian | 0 ~ 2.8.580 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100730 | 9.8 CRITICAL | Grid Protection Alliance openPDC and openHistorian Deserialization of Untrusted Data |
| CVE-2026-105278 | 9.8 CRITICAL | Grid Protection Alliance openPDC (Docker image) Use of Hard-coded Credentials |
| CVE-2026-104629 | 8.8 HIGH | Grid Protection Alliance openPDC and openHistorian Use of Externally-Controlled Input to S |
| CVE-2026-105281 | 7.5 HIGH | Grid Protection Alliance openPDC and openHistorian Missing Authentication for Critical Fun |
| CVE-2026-101022 | 4.3 MEDIUM | Grid Protection Alliance openPDC and openHistorian Server-Side Request Forgery (SSRF) |
No comments yet