IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Hitachi Energy FACTS Control Platform (FCP)

CRITICAL
CVSS 9.9
Date 2026-09-17T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Hitachi Energy is aware of vulnerabilities that affect the FACTS Control systems with GWS component listed in this document. An attacker exploiting these vulnerabilities can cause impact on confidentiality, integrity and availability of the product. Following FACTS Control systems with GWS component deployed from year 2020 onwards are likely affected by the above vulnerabilities. Product deployments without GWS component are not affected. • SVC Light (STATCOM) • Fixed Series Capacitor • Thyristor Controlled Series Capacitor • Static Var Compensator • Static Watt Compensator • Hybrid Synchronous Condensers Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The affected FCP versions are only applicable if GWS component is present.

// Vulnerabilities (5)

CVE ID CVSS Score Severity Description
CVE-2024-7940 8.3 high
CVE-2024-7940. The FACTS Control system with GWS product exposes a service that is intended for local only to all network interfaces without any authentication.
CVE-2024-3980 9.9 critical
CVE-2024-3980. The FACTS Control system with GWS allows an authenticated user input to control or influence paths or file names that are used in filesystem operations. If exploited the vulnerability allows the attacker to access or modify system files or other files that are critical to the application.
CVE-2024-3982 8.2 high
CVE-2024-3982. An attacker with local access to machine where FACTS Control system with GWS is installed, could enable the session logging supporting the product and try to exploit a session hijacking of an already established session. Note: By default, the session logging level is not enabled and only users with administrator rights can enable it.
CVE-2024-4872 9.9 critical
CVE-2024-4872. A vulnerability exists in the query validation of the FACTS Control system with GWS component. If exploited this could allow an authenticated attacker to inject code towards persistent data. Note that to successfully exploit this vulnerability an attacker must have a valid credential.
CVE-2024-7941 4.3 medium
CVE-2024-7941. A vulnerability exists in FACTS Control system with GWS where a HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified URL. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.

// Affected Products (1)

Vendor Product Asset Type Purdue Level Firmware
Hitachi Energy Unknown scada_server
L2
--

// Remediations (10)

Mitigation: Follow general mitigation factors
Follow general mitigation factors
Mitigation: Follow the mitigation strategy as described in the Mitigation Factors/Workarounds section
Follow the mitigation strategy as described in the Mitigation Factors/Workarounds section
Patch: Update to version 10.5 vulnerability patch 2025_01 or Update to version 10.6
Update to version 10.5 vulnerability patch 2025_01 or Update to version 10.6
Mitigation: Follow the mitigation strategy as described in the Mitigation Factors/Workarounds section
Follow the mitigation strategy as described in the Mitigation Factors/Workarounds section
Patch: Update to version 10.5 vulnerability patch 2025_01 or Update to version 10.6
Update to version 10.5 vulnerability patch 2025_01 or Update to version 10.6
Patch: Update to version 10.4 vulnerability patch 2025_01 or Update to version 10.6
Update to version 10.4 vulnerability patch 2025_01 or Update to version 10.6
Patch: Upgrade to version 3.4.0.0 Or apply general mitigation factors (Due to complexity of individual impl
Upgrade to version 3.4.0.0 Or apply general mitigation factors (Due to complexity of individual implementation of project, contact local account team for further information on possible upgrades and mitigation strategies.)
Patch: Update to version 10.5 vulnerability patch 2025_01 or Update to version 10.6
Update to version 10.5 vulnerability patch 2025_01 or Update to version 10.6
Mitigation: Apply the patch HF3 to HF6 sequentially Or apply general mitigation factors (Due to complexity of in
Apply the patch HF3 to HF6 sequentially Or apply general mitigation factors (Due to complexity of individual implementation of project, contact local account team for further information on possible upgrades and mitigation strategies.)
Patch: Apply the patch HF1 to HF6 sequentially Or apply general mitigation factors (Due to complexity of in
Apply the patch HF1 to HF6 sequentially Or apply general mitigation factors (Due to complexity of individual implementation of project, contact local account team for further information on possible upgrades and mitigation strategies.)

// References