Critical Vulnerabilities in Hitachi Energy FCP Threaten Industrial Control Systems
Multiple critical vulnerabilities — including authentication bypass, code injection, and path traversal — were discovered in Hitachi Energy's FACTS Control Platform (FCP), affecting versions deployed since 2020. With CVSS scores reaching 9.9, these flaws could allow attackers to fully compromise the confidentiality, integrity, and availability of industrial energy control systems. The presence of the GWS component significantly expands the attack surface, highlighting how optional or integrated components in OT/ICS platforms can introduce severe risk. Unpatched industrial control systems in energy infrastructure are high-value targets, and delayed remediation in these environments can have cascading real-world consequences.
Tactical Insight
Immediate actions
- Apply Hitachi Energy's security advisory patches or upgrades to FCP versions beyond 4.1.1 without delay.
- Isolate affected FCP deployments (especially those with the GWS component) from untrusted networks until patching is complete.
- Audit all FCP deployments from 2020 onwards to confirm which systems have the GWS component enabled.
Long-term improvements
- Maintain a comprehensive, up-to-date inventory of all ICS/OT software components, versions, and optional modules.
- Implement strict network segmentation to ensure FACTS Control Platforms are never directly accessible from corporate IT or internet-facing networks.
- Establish a formal vulnerability management program tailored to OT/ICS environments, including vendor advisory monitoring.
Detection measures
- Deploy ICS-aware intrusion detection systems (IDS) to monitor for anomalous authentication attempts or unusual command injection patterns on FCP systems.
- Enable and centralize logging for all authentication events and administrative actions on OT platforms to support rapid incident detection.
- Subscribe to ICS-CERT and Hitachi Energy security advisories to receive timely notification of future vulnerabilities.