Ghostwire

CVE-2026-101022: A Modbus connection feature on openPDC accepts a caller-specified destination address and port with no restriction on...

MEDIUM CVSS 0.0

Published: October 9, 2026 | Last Modified: October 9, 2026

Description

A Modbus connection feature on openPDC accepts a caller-specified destination address and port with no restriction on which internal hosts may be targeted. An authenticated user can attempt connections to arbitrary internal network destinations, revealing which destinations are reachable. With repeated attempts, an attacker may be able to map the internal network.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References