VYPR
advisoryPublished Sep 17, 2026· 1 source

Critical Vulnerabilities in Hitachi Energy FACTS Control Platform Threaten Power Grid Security

CISA has issued a critical alert detailing multiple severe vulnerabilities in Hitachi Energy's FACTS Control Platform (FCP) with the GWS component, potentially impacting global power grid operations.

CISA has issued a critical alert for multiple vulnerabilities affecting Hitachi Energy's FACTS Control Platform (FCP), specifically those incorporating the GWS component. These vulnerabilities, collectively tracked under CVE-2024-4872, CVE-2024-3980, CVE-2024-3982, CVE-2024-7940, and CVE-2024-7941, pose a significant risk to the confidentiality, integrity, and availability of critical power grid control systems deployed worldwide.

The affected FCP versions range from 3.4.0 through 4.1.1. It is crucial to note that only deployments including the GWS component are vulnerable; systems without it are not impacted. The affected products are integral to various power grid control systems, including SVC Light (STATCOM), Fixed Series Capacitor, Thyristor Controlled Series Capacitor, Static Var Compensator, Static Watt Compensator, and Hybrid Synchronous Condensers, with deployments dating back to 2020 potentially at risk.

Among the identified vulnerabilities, CVE-2024-4872 allows an authenticated attacker to inject code for persistent data manipulation through query validation flaws. CVE-2024-3980, a path traversal vulnerability, enables an authenticated user to access or modify critical system files by controlling file paths. CVE-2024-3982, a session hijacking vulnerability, requires local access and administrator privileges to enable session logging, allowing an attacker to hijack established sessions.

Furthermore, CVE-2024-7940 exposes a service intended for local use to all network interfaces without any authentication, significantly broadening the attack surface. The cumulative impact of these vulnerabilities is rated as CRITICAL, with CVSS v3.1 base scores reaching up to 9.9. Exploitation could lead to unauthorized data access, system manipulation, and denial-of-service conditions, severely disrupting power grid operations.

Hitachi Energy has acknowledged these vulnerabilities and provided a security advisory (8DBD000229) detailing mitigation and remediation steps. While specific patches are not detailed in the CISA alert, users are advised to follow general mitigation factors and consult the vendor's advisory for comprehensive guidance. The company is headquartered in Switzerland, and its affected products are deployed globally, underscoring the widespread potential impact.

The alert highlights the critical nature of securing industrial control systems (ICS) and operational technology (OT) environments. The interconnectedness of modern power grids means that a single vulnerability in a control platform can have cascading effects, potentially leading to widespread outages or instability. The presence of multiple critical vulnerabilities in a single platform underscores the need for rigorous security testing and prompt patching by vendors.

Organizations operating these Hitachi Energy FACTS Control systems are urged to prioritize the assessment of their GWS component's presence and version. Immediate review of the vendor's security advisory and implementation of recommended mitigation strategies are paramount to safeguarding critical infrastructure against potential exploitation. The global deployment of these systems means that coordinated action is essential to prevent a significant disruption to energy supply.

This advisory serves as a stark reminder of the ongoing threats facing the energy sector. As critical infrastructure becomes increasingly digitized and interconnected, the attack surface expands, necessitating continuous vigilance and robust security practices from both vendors and operators to ensure the resilience of essential services.

Synthesized by Vypr AI