Horizon Alert
Summary of the vulnerability and why it matters
The published Docker image for openPDC includes a fixed administrative credential, allowing unauthorized access to gain full administrative control of the application if the management interface is accessible. This vulnerability could allow an attacker to compromise the application's administrative functions. The main concern is confirming relevance and exposure.
- Fixed credential grants full admin control.
- Critical infrastructure component requires attention.
- Understand relevance and potential exposure.
Attack Path
How an attacker could exploit the issue
An attacker with network access to openPDC's management interface can use a default administrative credential to gain full control of the application. This is possible because the published Docker image includes a hardcoded password that is not changed on first use. Once authenticated, the attacker can perform any administrative action within the application.
- Network access required.
- Default credential allows login.
- Full administrative control gained.
Live Threat
Current exploitation, exposure, and threat context
An attacker with network access to the management interface could gain full administrative control of the openPDC application by using a fixed, default credential. This could affect the application's service behavior and any system data it manages.
- Application administrative control.
- Authentication via default credentials.
- Potential for unauthorized application control.
Operational Fix
Recommended remediation, mitigation, and detection steps
The openPDC management interface is a likely target for compromise due to its network accessibility and critical function in data aggregation. Infrastructure or platform teams responsible for openPDC deployments should prioritize identifying all instances of this software. Once located, confirm network reachability and business criticality to assign ownership and plan remediation based on the assessed risk.
- Infrastructure or platform teams own this.
- Verify network exposure and criticality.
- Plan remediation based on risk.