Skip to content
Threat Feed

Vendor

Hitachi Energy

5 briefs RSS
critical advisory

Multiple Critical Vulnerabilities in Hitachi Energy FACTS Control Platform

Hitachi Energy FACTS Control Platform (FCP) units equipped with the GWS component are affected by multiple critical vulnerabilities, including path traversal and authentication bypass, potentially leading to unauthorized system access or modification.

FACTS Control Platform ics energy ot vulnerability
2t 5c
medium advisory

Multiple Vulnerabilities in Hitachi Energy RTU500

Hitachi Energy RTU500 devices are impacted by multiple vulnerabilities that allow attackers to induce Denial-of-Service, exfiltrate authentication credentials, and bypass security controls.

RTU500
1t 5c
high advisory

Hitachi Energy PROMOD V Insecure HTTP Transmission Vulnerability (CVE-2026-10763)

Hitachi Energy PROMOD V versions 1.0.10 and prior are affected by CVE-2026-10763, an insecure HTTP transmission vulnerability that allows attackers to intercept or manipulate sensitive data in transit, potentially leading to credential theft, session hijacking, or unauthorized access, impacting the energy sector globally.

PROMOD V <= 1.0.10 ics ot vulnerability http-insecurity data-in-transit cve
2t 1c
medium advisory

CISA ICS Security Advisories Address Vulnerabilities in Multiple Vendor Products

CISA published ICS advisories addressing vulnerabilities in products from ABB, Hitachi Energy, Kieback & Peter, ScadaBR, Siemens, and ZKTeco, recommending mitigations and updates.

B&R Automation Runtime +10 ics scada vulnerability
2r
medium advisory

Hitachi Energy GMS600 Vulnerable to Bleichenbacher Attack via CVE-2022-4304

Hitachi Energy GMS600 versions 1.3.0 and 1.3.1 are affected by CVE-2022-4304, a vulnerability in the OpenSSL RSA Decryption implementation; an attacker could exploit this timing-based side channel to recover plaintext across a network in a Bleichenbacher-style attack by sending trial messages to the server and recording processing times, eventually decrypting application data.

GMS600 versions 1.3.0 and 1.3.1 bleichenbacher timing attack openssl critical infrastructure
2r 1t 1c