CISA Advisory Flags Two Critical Flaws in Hitachi Energy Grid Control Platform

Electrical substation protected by security and condition-monitoring systems

CISA published an advisory covering five vulnerabilities in Hitachi Energy’s FACTS Control Platform (FCP), software used to manage Flexible AC Transmission Systems that stabilize voltage and power flow on electric grids. Two of the flaws, CVE-2024-4872 and CVE-2024-3980, are rated 9.9 (Critical) on the CVSS v3.1 scale; a third, CVE-2024-7940, is rated 8.3 (High); a fourth, CVE-2024-3982, is rated 8.2 (High); and a fifth, CVE-2024-7941, is rated 4.3 (Medium).

According to CISA, the flaws include improper neutralization of special elements in data query logic, path traversal, authentication bypass by capture-replay, missing authentication for a critical function, and open redirect. An authenticated attacker could chain these to inject code, access critical files, hijack sessions, bypass authentication or run phishing attacks against operators. Hitachi Energy says only FCP deployments with the GWS component installed since 2020 are affected, spanning FCP versions 3.4.0 through 4.1.1. The company’s advisory 8DBD000229 outlines remediation; interim mitigations include isolating control systems behind firewalls, requiring VPNs for remote access and enforcing strong password policies.

Why it matters

FACTS platforms sit inside the control layer that keeps transmission voltage stable — CISA lists the affected sector as Energy, and a successful chained exploit could let an authenticated attacker manipulate grid-stabilization logic rather than simply steal data.

Sources

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *