Executive brief
Trac PDBM is a database manager used in industrial control and operational technology environments. A security flaw exists where the software uses a fixed, secret key hidden inside its own code to protect administrative passwords. An attacker who already has high-level access to the computer running this software can find this key, unlock the administrative password, and take full control of the management interface, potentially disrupting industrial processes.
Technical details
The PDBM application (specifically PDBM.exe) contains a hard-coded cryptographic secret (CWE-798) used by its internal encryption routines. This secret is utilized to decrypt administrative credentials stored in the application's configuration file. Because the secret is static across all installations of version 1.0.0.0, an attacker with local high privileges can extract the key from the binary and decrypt the stored password. This grants the attacker administrative access to the PDBM management interface and potentially connected ICS/OT systems. The vulnerability is resolved in version 2.0.0.0, which replaced the hard-coded mechanism with a hash-based authentication system.
Affected products
- Trac d.o.o. PDBM (Process Database Manager) 1.0.0.0
Timeline
- 2026-01-15: other: Initial report submitted to SI-CERT
- 2026-02-03: other: Vendor formally notified
- 2026-05-29: advisory: SI-CERT advisory published
- 2026-06-01: disclosed: NVD publication date
- 2020: patched: Version 2.0.0.0 released (per vendor timeline in advisory)