{ "document": { "acknowledgments": [ { "names": [ "Shubham Raj (Cipher)" ], "organization": "Causal Security", "summary": "reported these vulnerabilities", "urls": [ "https://causalsecurity.com/" ] } ], "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Disclosure is not limited", "tlp": { "label": "WHITE", "url": "https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage" } }, "lang": "en-US", "notes": [ { "category": "other", "text": "Successful exploitation of these vulnerabilities could allow an attacker to gain administrative control of the system, execute arbitrary code, access sensitive operational data, or map the internal network.", "title": "Advisory Summary" }, { "category": "other", "text": "Energy", "title": "Critical infrastructure sectors" }, { "category": "other", "text": "Worldwide", "title": "Countries/areas deployed" }, { "category": "other", "text": "United States", "title": "Company headquarters location" }, { "category": "legal_disclaimer", "text": "This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).", "title": "Legal Notice and Terms of Use" }, { "category": "general", "text": "CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.", "title": "Recommended Practices" }, { "category": "general", "text": "Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.", "title": "Recommended Practices" }, { "category": "general", "text": "Locate control system networks and remote devices behind firewalls and isolating them from business networks.", "title": "Recommended Practices" }, { "category": "general", "text": "When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.", "title": "Recommended Practices" }, { "category": "general", "text": "CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.", "title": "Recommended Practices" }, { "category": "general", "text": "CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.", "title": "Recommended Practices" }, { "category": "general", "text": "CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.", "title": "Recommended Practices" }, { "category": "general", "text": "Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.", "title": "Recommended Practices" }, { "category": "general", "text": "Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.", "title": "Recommended Practices" }, { "category": "general", "text": "CISA also recommends users take the following measures to protect themselves from social engineering attacks:", "title": "Recommended Practices" }, { "category": "general", "text": "Do not click web links or open attachments in unsolicited email messages.", "title": "Recommended Practices" }, { "category": "general", "text": "Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.", "title": "Recommended Practices" }, { "category": "general", "text": "Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.", "title": "Recommended Practices" }, { "category": "general", "text": "No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.", "title": "Recommended Practices" } ], "publisher": { "category": "coordinator", "contact_details": "central@cisa.dhs.gov", "name": "CISA", "namespace": "https://www.cisa.gov/" }, "references": [ { "category": "self", "summary": "ICSA Advisory ICSA-26-281-02 JSON", "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-281-02.json" }, { "category": "external", "summary": "Recommended Practices", "url": "https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01" }, { "category": "external", "summary": "Recommended Practices", "url": "https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" }, { "category": "external", "summary": "Recommended Practices", "url": "https://www.cisa.gov/topics/industrial-control-systems" }, { "category": "external", "summary": "Recommended Practices", "url": "https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" }, { "category": "external", "summary": "Recommended Practices", "url": "https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" }, { "category": "external", "summary": "Recommended Practices", "url": "https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b" } ], "title": "Grid Protection Alliance openPDC and openHistorian", "tracking": { "current_release_date": "2026-10-08T06:00:00.000000Z", "generator": { "date": "2026-10-05T17:24:43.196284Z", "engine": { "name": "CISA CSAF Generator", "version": "2.0.0" } }, "id": "ICSA-26-281-02", "initial_release_date": "2026-10-08T06:00:00.000000Z", "revision_history": [ { "date": "2026-10-08T06:00:00.000000Z", "number": "1", "summary": "Initial Publication" } ], "status": "final", "version": "1" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_version_range", "name": "<2.9.477", "product": { "name": "Grid Protection Alliance openPDC <2.9.477", "product_id": "CSAFPID-0001" } }, { "category": "product_version_range", "name": "<2.9.482", "product": { "name": "Grid Protection Alliance openPDC <2.9.482", "product_id": "CSAFPID-0002" } } ], "category": "product_name", "name": "openPDC" }, { "branches": [ { "category": "product_version_range", "name": "<2.9.477", "product": { "name": "Grid Protection Alliance openPDC (Docker image) <2.9.477", "product_id": "CSAFPID-0003" } }, { "category": "product_version_range", "name": "<2.9.482", "product": { "name": "Grid Protection Alliance openPDC (Docker image) <2.9.482", "product_id": "CSAFPID-0004" } } ], "category": "product_name", "name": "openPDC (Docker image)" }, { "branches": [ { "category": "product_version_range", "name": "<2.8.580", "product": { "name": "Grid Protection Alliance openHistorian <2.8.580", "product_id": "CSAFPID-0005" } }, { "category": "product_version_range", "name": "<2.8.585", "product": { "name": "Grid Protection Alliance openHistorian <2.8.585", "product_id": "CSAFPID-0006" } } ], "category": "product_name", "name": "openHistorian" } ], "category": "vendor", "name": "Grid Protection Alliance" } ] }, "vulnerabilities": [ { "cve": "CVE-2026-100730", "cwe": { "id": "CWE-502", "name": "Deserialization of Untrusted Data" }, "notes": [ { "category": "summary", "text": "A service console interface on openPDC and openHistorian deserializes a client-supplied data structure. On systems using Windows Authentication, an attacker must already be authenticated to reach this function; on systems without Windows Authentication, this is reachable by an unauthenticated network attacker. This allows an attacker to trigger deserialization of an arbitrary object graph, which could allow remote code execution under the privileges of the affected service account.", "title": "Vulnerability Summary" }, { "category": "details", "text": "SSVCv2/E:N/A:Y/2026-10-05T17:24:43.197646Z", "title": "SSVC" } ], "product_status": { "known_affected": [ "CSAFPID-0002", "CSAFPID-0004", "CSAFPID-0006" ] }, "references": [ { "category": "external", "summary": "www.cve.org", "url": "https://www.cve.org/CVERecord?id=CVE-2026-100730" }, { "category": "external", "summary": "cwe.mitre.org", "url": "https://cwe.mitre.org/data/definitions/502.html" }, { "category": "external", "summary": "www.first.org", "url": "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" }, { "category": "external", "summary": "www.first.org", "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "remediations": [ { "category": "vendor_fix", "details": "Grid Protection Alliance has added additional validation into serialization logic in openPDC version 2.9.482 and later and openHistorian version 2.8.585 and later. Systems using Windows Authentication are additionally protected, as they require the attacker to already be authenticated to reach this function.", "product_ids": [ "CSAFPID-0002", "CSAFPID-0006" ], "url": "https://gridprotectionalliance.org/news-story.asp?ID=4056" }, { "category": "no_fix_planned", "details": "Grid Protection Alliance does not recommend production use of published Docker images in any case. The fix for this vulnerability has not been published to the Docker image.", "product_ids": [ "CSAFPID-0004" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "CSAFPID-0002", "CSAFPID-0004", "CSAFPID-0006" ] } ] }, { "cve": "CVE-2026-105281", "cwe": { "id": "CWE-306", "name": "Missing Authentication for Critical Function" }, "notes": [ { "category": "summary", "text": "The internal data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and retrieve the complete device and measurement topology of the system.", "title": "Vulnerability Summary" }, { "category": "details", "text": "SSVCv2/E:N/A:Y/2026-10-05T17:24:43.197884Z", "title": "SSVC" } ], "product_status": { "known_affected": [ "CSAFPID-0002", "CSAFPID-0004", "CSAFPID-0006" ] }, "references": [ { "category": "external", "summary": "www.cve.org", "url": "https://www.cve.org/CVERecord?id=CVE-2026-105281" }, { "category": "external", "summary": "cwe.mitre.org", "url": "https://cwe.mitre.org/data/definitions/306.html" }, { "category": "external", "summary": "www.first.org", "url": "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" }, { "category": "external", "summary": "www.first.org", "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" } ], "remediations": [ { "category": "vendor_fix", "details": "Grid Protection Alliance updated the default configuration to bind this interface to the local loopback address only. This change applies to new installations; existing installations upgraded from an earlier version retain their prior configuration and will not receive the new default automatically. Operators should verify their configuration explicitly and update the interface binding if it is still set to accept connections on all interfaces.", "product_ids": [ "CSAFPID-0002", "CSAFPID-0006" ] }, { "category": "no_fix_planned", "details": "Grid Protection Alliance does not recommend production use of published Docker images in any case. The fix for this vulnerability has not been published to the Docker image.", "product_ids": [ "CSAFPID-0004" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "version": "3.1" }, "products": [ "CSAFPID-0002", "CSAFPID-0004", "CSAFPID-0006" ] } ] }, { "cve": "CVE-2026-85479", "cwe": { "id": "CWE-306", "name": "Missing Authentication for Critical Function" }, "notes": [ { "category": "summary", "text": "The STTP-based data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and exchange data with it.", "title": "Vulnerability Summary" }, { "category": "details", "text": "SSVCv2/E:N/A:Y/2026-10-05T17:24:43.198057Z", "title": "SSVC" } ], "product_status": { "known_affected": [ "CSAFPID-0002", "CSAFPID-0004", "CSAFPID-0006" ] }, "references": [ { "category": "external", "summary": "www.cve.org", "url": "https://www.cve.org/CVERecord?id=CVE-2026-85479" }, { "category": "external", "summary": "cwe.mitre.org", "url": "https://cwe.mitre.org/data/definitions/306.html" }, { "category": "external", "summary": "www.first.org", "url": "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" }, { "category": "external", "summary": "www.first.org", "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N" } ], "remediations": [ { "category": "vendor_fix", "details": "Grid Protection Alliance updated the default configuration to bind this interface to the local loopback address only. This change applies to new installations; existing installations upgraded from an earlier version retain their prior configuration and will not receive the new default automatically. Operators should verify their configuration explicitly and update the interface binding if it is still set to accept connections on all interfaces.", "product_ids": [ "CSAFPID-0002", "CSAFPID-0006" ] }, { "category": "no_fix_planned", "details": "Grid Protection Alliance does not recommend production use of published Docker images in any case. The fix for this vulnerability has not been published to the Docker image.", "product_ids": [ "CSAFPID-0004" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "version": "3.1" }, "products": [ "CSAFPID-0002", "CSAFPID-0004", "CSAFPID-0006" ] } ] }, { "cve": "CVE-2026-101022", "cwe": { "id": "CWE-918", "name": "Server-Side Request Forgery (SSRF)" }, "notes": [ { "category": "summary", "text": "A Modbus connection feature on openPDC accepts a caller-specified destination address and port with no restriction on which internal hosts may be targeted. An authenticated user can attempt connections to arbitrary internal network destinations, revealing which destinations are reachable. With repeated attempts, an attacker may be able to map the internal network.", "title": "Vulnerability Summary" }, { "category": "details", "text": "SSVCv2/E:N/A:N/2026-10-05T17:24:43.198207Z", "title": "SSVC" } ], "product_status": { "known_affected": [ "CSAFPID-0002", "CSAFPID-0004", "CSAFPID-0006" ] }, "references": [ { "category": "external", "summary": "www.cve.org", "url": "https://www.cve.org/CVERecord?id=CVE-2026-101022" }, { "category": "external", "summary": "cwe.mitre.org", "url": "https://cwe.mitre.org/data/definitions/918.html" }, { "category": "external", "summary": "www.first.org", "url": "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" }, { "category": "external", "summary": "www.first.org", "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N" } ], "remediations": [ { "category": "mitigation", "details": "Grid Protection Alliance recommends restricting network access to modbus using a firewall, and disallowing connections to loopback and private (RFC 1918) address ranges unless explicitly required.", "product_ids": [ "CSAFPID-0002", "CSAFPID-0004", "CSAFPID-0006" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N", "version": "3.1" }, "products": [ "CSAFPID-0002", "CSAFPID-0004", "CSAFPID-0006" ] } ] }, { "cve": "CVE-2026-105278", "cwe": { "id": "CWE-798", "name": "Use of Hard-coded Credentials" }, "notes": [ { "category": "summary", "text": "The published Docker image for openPDC includes a fixed administrative credential with no forced change on first use. An attacker with network access to the management interface can authenticate using this credential and gain full administrative control of the application.", "title": "Vulnerability Summary" }, { "category": "details", "text": "SSVCv2/E:N/A:Y/2026-10-05T17:24:43.198354Z", "title": "SSVC" } ], "product_status": { "known_affected": [ "CSAFPID-0004" ] }, "references": [ { "category": "external", "summary": "www.cve.org", "url": "https://www.cve.org/CVERecord?id=CVE-2026-105278" }, { "category": "external", "summary": "cwe.mitre.org", "url": "https://cwe.mitre.org/data/definitions/798.html" }, { "category": "external", "summary": "www.first.org", "url": "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" }, { "category": "external", "summary": "www.first.org", "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "remediations": [ { "category": "no_fix_planned", "details": "Grid Protection Alliance does not recommend production use of published Docker images in any case. The fix for this vulnerability has not been published to the Docker image.", "product_ids": [ "CSAFPID-0004" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "CSAFPID-0004" ] } ] }, { "cve": "CVE-2026-104629", "cwe": { "id": "CWE-470", "name": "Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')" }, "notes": [ { "category": "summary", "text": "A component loading mechanism in openPDC and openHistorian will construct and run any specified type, which may be an invalid component to load. An attacker with an authenticated user account and the ability to place a file on the host filesystem can use this to run arbitrary constructor code, and this code runs with the privileges of the affected service account.", "title": "Vulnerability Summary" }, { "category": "details", "text": "SSVCv2/E:N/A:N/2026-10-05T17:24:43.198484Z", "title": "SSVC" } ], "product_status": { "known_affected": [ "CSAFPID-0001", "CSAFPID-0003", "CSAFPID-0005" ] }, "references": [ { "category": "external", "summary": "www.cve.org", "url": "https://www.cve.org/CVERecord?id=CVE-2026-104629" }, { "category": "external", "summary": "cwe.mitre.org", "url": "https://cwe.mitre.org/data/definitions/470.html" }, { "category": "external", "summary": "www.first.org", "url": "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" }, { "category": "external", "summary": "www.first.org", "url": "https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "remediations": [ { "category": "vendor_fix", "details": "Grid Protection Alliance has added additional verification and integrity checks of adapters in openPDC version 2.9.477 and later and openHistorian version 2.8.580 and later.", "product_ids": [ "CSAFPID-0001", "CSAFPID-0005" ], "url": "https://gridprotectionalliance.org/news-story.asp?ID=4054" }, { "category": "no_fix_planned", "details": "Grid Protection Alliance does not recommend production use of published Docker images in any case. The fix for this vulnerability has not been published to the Docker image.", "product_ids": [ "CSAFPID-0003" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "CSAFPID-0001", "CSAFPID-0003", "CSAFPID-0005" ] } ] } ] }