Retour à la veille

CVE-2026-101022

Publié : 9 octobre 2026
Modifié : 9 octobre 2026
Lien officiel NVD
Score CVSS
4.3
MEDIUM

Description détaillée

A Modbus connection feature on openPDC accepts a caller-specified destination address and port with no restriction on which internal hosts may be targeted. An authenticated user can attempt connections to arbitrary internal network destinations, revealing which destinations are reachable. With repeated attempts, an attacker may be able to map the internal network.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Références et Patchs