Back to Feed
VulnerabilitiesSep 17, 2026

Hitachi Energy FACTS Control Platform (FCP)

Hitachi Energy discloses critical vulnerabilities in FACTS Control Platform with GWS component.

Summary

Hitachi Energy has announced multiple critical vulnerabilities affecting its FACTS Control Platform (FCP) when the GWS component is present, particularly in deployments from 2020 onwards. These vulnerabilities, including code injection, path traversal, authentication bypass, missing authentication, and open redirect, carry CVSS scores up to 9.9 and could allow authenticated attackers to compromise confidentiality, integrity, and availability. Affected versions range from FCP 3.4.0 to 4.1.1, and mitigation guidance is available in Hitachi Energy's security advisory.

Full text

ICS Advisory Hitachi Energy FACTS Control Platform (FCP) Release DateSeptember 17, 2026 Alert CodeICSA-26-260-03 Related topics: Industrial Control System Vulnerabilities , Industrial Control Systems View CSAF Summary Hitachi Energy is aware of vulnerabilities that affect the FACTS Control systems with GWS component listed in this document. An attacker exploiting these vulnerabilities can cause impact on confidentiality, integrity and availability of the product. Following FACTS Control systems with GWS component deployed from year 2020 onwards are likely affected by the above vulnerabilities. Product deployments without GWS component are not affected. • SVC Light (STATCOM) • Fixed Series Capacitor • Thyristor Controlled Series Capacitor • Static Var Compensator • Static Watt Compensator • Hybrid Synchronous Condensers Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The affected FCP versions are only applicable if GWS component is present. The following versions of Hitachi Energy FACTS Control Platform (FCP) are affected: FACTS Control Platform (FCP) 3.4.0, 3.7.0, 3.8.0, 3.10.0, 3.12.0, 3.14.0, 3.15.0, 4.0.0, 4.0.1, 4.1.0, 4.1.1 (CVE-2024-4872, CVE-2024-3980, CVE-2024-3982, CVE-2024-7940, CVE-2024-7941) CVSS Vendor Equipment Vulnerabilities v3 9.9 Hitachi Energy Hitachi Energy FACTS Control Platform (FCP) Improper Neutralization of Special Elements in Data Query Logic, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Authentication Bypass by Capture-replay, Missing Authentication for Critical Function, URL Redirection to Untrusted Site ('Open Redirect') Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2024-4872 A vulnerability exists in the query validation of the FACTS Control system with GWS component. If exploited this could allow an authenticated attacker to inject code towards persistent data. Note that to successfully exploit this vulnerability an attacker must have a valid credential. View CVE Details Affected Products Hitachi Energy FACTS Control Platform (FCP) Vendor:Hitachi Energy Product Version:FACTS Control Platform (FCP) version 3.4.0, FACTS Control Platform (FCP) version 3.7.0, FACTS Control Platform (FCP) version 3.8.0, FACTS Control Platform (FCP) version 3.10.0, FACTS Control Platform (FCP) version 3.12.0, FACTS Control Platform (FCP) version 3.14.0, FACTS Control Platform (FCP) version 3.15.0, FACTS Control Platform (FCP) version 4.0.0, FACTS Control Platform (FCP) version 4.0.1, FACTS Control Platform (FCP) version 4.1.0, FACTS Control Platform (FCP) version 4.1.1 Product Status:known_affected Remediations MitigationFollow general mitigation factors. For more information see the associated Hitachi Energy security advisory 8DBD000229. Relevant CWE: CWE-943 Improper Neutralization of Special Elements in Data Query Logic Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.9 CRITICAL CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVE-2024-3980 The FACTS Control system with GWS allows an authenticated user input to control or influence paths or file names that are used in filesystem operations. If exploited the vulnerability allows the attacker to access or modify system files or other files that are critical to the application. View CVE Details Affected Products Hitachi Energy FACTS Control Platform (FCP) Vendor:Hitachi Energy Product Version:FACTS Control Platform (FCP) version 3.4.0, FACTS Control Platform (FCP) version 3.7.0, FACTS Control Platform (FCP) version 3.8.0, FACTS Control Platform (FCP) version 3.10.0, FACTS Control Platform (FCP) version 3.12.0, FACTS Control Platform (FCP) version 3.14.0, FACTS Control Platform (FCP) version 3.15.0, FACTS Control Platform (FCP) version 4.0.0, FACTS Control Platform (FCP) version 4.0.1, FACTS Control Platform (FCP) version 4.1.0, FACTS Control Platform (FCP) version 4.1.1 Product Status:known_affected Remediations MitigationFollow general mitigation factors. For more information see the associated Hitachi Energy security advisory 8DBD000229. Relevant CWE: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.9 CRITICAL CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVE-2024-3982 An attacker with local access to machine where FACTS Control system with GWS is installed, could enable the session logging supporting the product and try to exploit a session hijacking of an already established session. Note: By default, the session logging level is not enabled and only users with administrator rights can enable it. View CVE Details Affected Products Hitachi Energy FACTS Control Platform (FCP) Vendor:Hitachi Energy Product Version:FACTS Control Platform (FCP) version 3.10.0, FACTS Control Platform (FCP) version 3.12.0, FACTS Control Platform (FCP) version 3.14.0, FACTS Control Platform (FCP) version 3.15.0, FACTS Control Platform (FCP) version 4.0.0, FACTS Control Platform (FCP) version 4.0.1, FACTS Control Platform (FCP) version 4.1.0, FACTS Control Platform (FCP) version 4.1.1 Product Status:known_affected Remediations MitigationFollow general mitigation factors. For more information see the associated Hitachi Energy security advisory 8DBD000229. Relevant CWE: CWE-294 Authentication Bypass by Capture-replay Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.2 HIGH CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H CVE-2024-7940 The FACTS Control system with GWS product exposes a service that is intended for local only to all network interfaces without any authentication. View CVE Details Affected Products Hitachi Energy FACTS Control Platform (FCP) Vendor:Hitachi Energy Product Version:FACTS Control Platform (FCP) version 3.14.0, FACTS Control Platform (FCP) version 3.15.0, FACTS Control Platform (FCP) version 4.0.0, FACTS Control Platform (FCP) version 4.0.1, FACTS Control Platform (FCP) version 4.1.0, FACTS Control Platform (FCP) version 4.1.1 Product Status:known_affected Remediations MitigationFollow general mitigation factors. For more information see the associated Hitachi Energy security advisory 8DBD000229. Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.3 HIGH CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H CVE-2024-7941 A vulnerability exists in FACTS Control system with GWS where a HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified URL. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials. View CVE Details Affected Products Hitachi Energy FACTS Control Platform (FCP) Vendor:Hitachi Energy Product Version:FACTS Control Platform (FCP) version 3.15.0, FACTS Control Platform (FCP) version 4.1.0, FACTS Control Platform (FCP) version 4.1.1 Product Status:known_affected Remediations MitigationFollow general mitigation factors. For more information see the associated Hitachi Energy security advisory 8DBD000229. Relevant CWE: CWE-601 URL Redirection to Untrusted Site ('Open Redirect') Metrics CVSS Version Base Score Base Severity Vector String 3.1 4.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N Acknowledgments Hitachi Energy reported these vulnerabilities to CISA. Notice The information in this document is subject to change without notice and should not be construed as a commitment by Hitachi Energy. Hitachi Energy provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall Hitachi Energy or any of its suppliers be liable for direct, indirect, special, in

Indicators of Compromise

  • cve — CVE-2024-4872
  • cve — CVE-2024-3980
  • cve — CVE-2024-3982
  • cve — CVE-2024-7940
  • cve — CVE-2024-7941

Entities

FACTS Control Platform (FCP) (product)Hitachi Energy (vendor)GWS component (technology)