Back to all lessons
Awareness Lessons
3 months ago

Hitachi Energy PROMOD V Exposes ICS to Credential Theft via Insecure HTTP

The vulnerability in Hitachi Energy's PROMOD V product stems from the use of insecure HTTP transmission instead of encrypted HTTPS, a fundamental configuration failure that leaves sensitive data — including credentials — exposed to interception or manipulation via man-in-the-middle attacks. This is particularly critical in industrial control system (ICS) environments where compromised credentials can lead to unauthorized control of operational technology (OT) infrastructure. The risk is amplified when these systems are inadvertently exposed to broader networks without proper isolation. Insecure communication protocols in critical infrastructure represent a systemic weakness that attackers actively target, as the consequences can extend beyond data theft to physical operational disruption.

Tactical Insight

Immediate actions

  • Replace all HTTP communications with TLS-enforced HTTPS across PROMOD V deployments and verify certificate validity.
  • Isolate affected PROMOD V systems behind dedicated firewalls and restrict inbound/outbound traffic to only known, required endpoints.

Long-term improvements

  • Enforce a secure-by-default configuration baseline for all ICS/OT products that mandates encrypted transport protocols at deployment.
  • Maintain a comprehensive OT asset inventory with protocol-level visibility to detect any unencrypted communication channels proactively.
  • Implement network segmentation with demilitarized zones (DMZs) to separate ICS environments from corporate IT networks.

Detection measures

  • Deploy network traffic analysis tools capable of alerting on cleartext credential transmission or unexpected HTTP sessions within OT environments.
  • Establish continuous monitoring and logging of authentication events on PROMOD V systems to detect unauthorized access attempts.