ics-otregulatorNewsThe Broadside1 min read

Five Critical CVEs Hit Hitachi Energy FACTS Control Platform

Two of the five carry a CVSS 9.9, and the affected controllers with the GWS component have been deployed across the global energy sector since 2020.


TL;DR

CISA published an advisory covering five vulnerabilities in Hitachi Energy's FACTS Control Platform (FCP) when the GWS component is present. The affected versions span FCP 3.4.0 through 4.1.1, deployed worldwide in the energy sector from 2020 onward. Two of the CVEs carry a 9.9 critical score: CVE-2024-4872 permits code injection toward persistent data by an authenticated attacker, and CVE-2024-3980 enables path traversal to access or modify system files. The advisory directs operators to Hitachi Energy security advisory 8DBD000229 for mitigation; patch availability and timeline were not stated.

Hitachi Energy's FACTS Control Platform (the control system behind SVC Light (STATCOM), static var compensators, series capacitors, and hybrid synchronous condensers) has five newly disclosed vulnerabilities when the GWS component is installed. The affected versions run from FCP 3.4.0 through 4.1.1, covering 11 specific versions. Deployments without the GWS component are unaffected.

Two of the five are critical at CVSS 9.9. CVE-2024-4872, an improper-neutralization flaw in data query logic, lets an authenticated attacker inject code toward persistent data. CVE-2024-3980 is a path-traversal vulnerability that allows an authenticated user to access or modify filesystem files critical to the application. Both carry the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, network-exploitable, low complexity, with scope change and high impact across confidentiality, integrity, and availability.

The remaining three are significant but lower severity: CVE-2024-3982 (CVSS 8.2) enables session hijacking via capture-replay, but only when an attacker has local access and an administrator has enabled session logging, which is off by default. CVE-2024-7940 (CVSS 8.3) exposes a locally intended service across all network interfaces without authentication. CVE-2024-7941 (CVSS 4.3) is an open-redirect flaw that could be used in phishing to steal credentials.

Hitachi Energy's advisory lists "general mitigation factors" and refers operators to its full security advisory 8DBD000229. No patch release date or firmware update schedule appears in the CISA publication. The affected equipment list includes SVC Light (STATCOM), Fixed Series Capacitor, Thyristor Controlled Series Capacitor, Static Var Compensator, Static Watt Compensator, and Hybrid Synchronous Condensers, all deployed worldwide in the energy sector.

This follows a string of ICS advisories for Hitachi Energy products. Research [3] shows a November 2024 advisory covering the same five CVE identifiers in the MicroSCADA Pro/X SYS600 product line, updated April 2025. The shared CVE identifiers between FCP and MicroSCADA Pro/X suggest overlapping software components across Hitachi Energy's grid product portfolio.


Published ·Deep Fathom