Tec Nikan
فارسی
Talk to us
All news

Two Critical Flaws in Hitachi Energy's FACTS Control Platform

ICSA-26-260-03 lists five vulnerabilities in the platform that controls SVCs and STATCOMs, two of them at CVSS 9.9, across eleven platform versions.

transmissionFACTSHitachi Energygrid securityICS advisory

CISA published ICSA-26-260-03 on 17 September, covering five vulnerabilities in the Hitachi Energy FACTS Control Platform — the control system behind flexible AC transmission equipment such as static VAR compensators and STATCOMs.

Two entries score 9.9. CVE-2024-4872 is a query validation bypass that CISA describes as allowing an authenticated attacker to inject code towards persistent data. CVE-2024-3980 is a path traversal enabling unauthorised file access. Behind them sit CVE-2024-3982, session hijacking by replay, at 8.2; CVE-2024-7940, an unauthenticated network service exposure, at 8.3; and CVE-2024-7941, an open redirect usable for phishing, at 4.3.

Eleven FCP versions are listed — 3.4.0, 3.7.0, 3.8.0, 3.10.0, 3.12.0, 3.14.0, 3.15.0, 4.0.0, 4.0.1, 4.1.0 and 4.1.1 — but the scope is narrower than that suggests. Only deployments that include the GWS component from 2020 onward are affected. Patch guidance is in Hitachi Energy advisory 8DBD000229, and CISA's generic mitigations apply: keep control systems off the internet, put them behind firewalls with minimal port exposure, use VPNs for remote access.

FACTS equipment holds transmission voltage and damps oscillations, which places its control platform among the higher-consequence assets on the grid side of a substation fence. The practical difficulty is not the score but the change process. Fixing this runs through a vendor advisory number and a transmission owner's change management, which in North America means a CIP-010 window and an outage negotiated well in advance — not an afternoon's patching.

Want to work with us?

Tell us what you're building and we'll help you scope the first deployment.