{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3ahitachienergymicroscada_x_sys60010.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:fixpack_1:*:*:*:*:*:*","cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:fixpack_2_hf1:*:*:*:*:*:*","cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:fixpack_2_hf2:*:*:*:*:*:*","cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:fixpack_2_hf3:*:*:*:*:*:*","cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:fixpack_2_hf4:*:*:*:*:*:*","cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:fixpack_2_hf5:*:*:*:*:*:*","cpe:2.3:a:hitachienergy:microscada_x_sys600:*:*:*:*:*:*:*:*","cpe:2.3:a:hitachienergy:microscada_x_sys600:10.5:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.9,"id":"CVE-2024-3980"},{"cvss":9.9,"id":"CVE-2024-4872"},{"cvss":8.2,"id":"CVE-2024-3982"},{"cvss":8.3,"id":"CVE-2024-7940"},{"cvss":4.3,"id":"CVE-2024-7941"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FACTS Control Platform (FCP) (3.4.0, 3.7.0, 3.8.0, 3.10.0, 3.12.0, 3.14.0, 3.15.0, 4.0.0, 4.0.1, 4.1.0, 4.1.1)"],"_cs_severities":["critical"],"_cs_tags":["ics","energy","ot","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Hitachi Energy"],"content_html":"\u003cp\u003eHitachi Energy has disclosed a series of critical vulnerabilities affecting the FACTS Control Platform (FCP) specifically when the GWS (Gateway Service) component is present. The vulnerabilities impact systems deployed since 2020, including SVC Light (STATCOM), Fixed Series Capacitor, Thyristor Controlled Series Capacitor, Static Var Compensator, Static Watt Compensator, and Hybrid Synchronous Condensers. The vulnerabilities range from path traversal (CVE-2024-3980) and improper query neutralization (CVE-2024-4872) to authentication bypass via capture-replay (CVE-2024-3982) and missing authentication for critical service functions (CVE-2024-7940).\u003c/p\u003e\n\u003cp\u003eThese flaws pose a significant risk to the confidentiality, integrity, and availability of power grid control assets. Because the FCP is integrated into critical energy infrastructure, these vulnerabilities are highly sensitive for defenders operating in OT environments. Successful exploitation allows attackers to manipulate sensitive files, inject code, or interact with unauthenticated services, potentially leading to full system compromise or operational disruption.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe affected platforms are utilized in critical energy infrastructure worldwide. Successful exploitation could allow a remote or local attacker to modify control logic, access sensitive system configurations, or bypass authentication mechanisms. Given the nature of FACTS systems in stabilizing electrical grids, the potential impact includes severe operational instability, loss of control over grid stabilization hardware, and the compromise of sensitive power transmission control data.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification of all FACTS Control Platform (FCP) assets running the GWS component within the OT environment.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAudit network ingress to identify services exposed by the GWS component that should be restricted to local or trusted internal segment access only, specifically addressing CVE-2024-7940.\u003c/li\u003e\n\u003cli\u003eReview internal configuration and access logs for unauthorized file system operations or attempts to access restricted paths, which may indicate exploitation attempts for CVE-2024-3980.\u003c/li\u003e\n\u003cli\u003eEnforce strict role-based access control and disable unnecessary session logging features on FCP systems to mitigate the prerequisite requirements for CVE-2024-3982.\u003c/li\u003e\n\u003cli\u003eCoordinate with Hitachi Energy representatives to obtain the specific security advisory 8DBD000229 for remediation instructions and patch availability for affected FCP versions.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-17T17:11:25Z","date_published":"2026-09-17T17:11:25Z","id":"https://feed.craftedsignal.io/briefs/2026-09-hitachi-fcp-vulns/","summary":"Hitachi Energy FACTS Control Platform (FCP) units equipped with the GWS component are affected by multiple critical vulnerabilities, including path traversal and authentication bypass, potentially leading to unauthorized system access or modification.","title":"Multiple Critical Vulnerabilities in Hitachi Energy FACTS Control Platform","url":"https://feed.craftedsignal.io/briefs/2026-09-hitachi-fcp-vulns/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:hitachienergy:microscada_x_sys600:10.5:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}