Skip to content

Security1 publisher2 min readPublished

CISA ties five 2024 CVEs to Hitachi Energy grid stabilization controllers installed since 2020

CISA's advisory covers eleven FACTS Control Platform versions across six product families, and it applies only where the GWS component is present. A utility's first job is establishing which installations have it.

The Watch · Security desk

Illustration accompanying CISA ties five 2024 CVEs to Hitachi Energy grid stabilization controllers installed since 2020

What happened

  • CISA advisory ICSA-26-260-03 lists five 2024 CVEs against Hitachi Energy's FACTS Control Platform. The version list applies only where the product's GWS component is installed.
  • Eleven FCP versions are named as known affected, running from 3.4.0 through 4.1.1.
  • The injection and path traversal flaws require a valid credential. The session hijacking issue requires local access plus session logging that only an administrator can enable.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint Scope turns on the presence of a software component, not on a version string, so a patch process driven by CVE feeds cannot decide whether a particular substation asset is affected.
  • exposure Because every fully described path starts with a credential or with local access, the risk sits with maintenance accounts and engineering workstations that reach the FACTS control network.
  • decision Compensating controls are the option available in the advisory. Applying them to reactive power equipment means scheduling around the availability of transmission assets.
  • precedent An ICS advisory landing about two years after the CVE year sets the expectation for how late energy asset owners hear about vendor-tracked flaws.

An attacker who already holds a valid credential on a FACTS Control system with GWS can inject code toward persistent data through the query validation flaw, classified in the advisory as CWE-943 [6]. Under CWE-22, authenticated input can influence the paths and file names used in filesystem operations, which gets the attacker access to or modification of files critical to the application [7]. The third described weakness is capture-replay, CWE-294: a user with local access to the machine can switch on the product's session logging and attempt to hijack an established session, and CISA notes that the logging level is disabled by default and that only administrators can enable it [8]. A fourth entry concerns a service the product exposes [15].

That capture-replay entry is listed against 3.10.0 and later, which is eight of the eleven versions in the advisory; 3.4.0, 3.7.0 and 3.8.0 appear only under the query validation and path traversal entries [10].

Whether the GWS component is installed decides the scope. CISA states that deployments without GWS are not affected, and that the affected version list applies only where the component is present [4]. The build record for each installation is what tells a control engineer whether a given compensator is in scope. The equipment named is transmission-side: SVC Light (STATCOM), fixed series capacitors, thyristor controlled series capacitors, static var compensators, static watt compensators and hybrid synchronous condensers, deployed from 2020 onward [5]. CISA lists the sector as energy and the deployment area as worldwide [12].

The five identifiers carry 2024 numbers [2]. CISA's advisory number is ICSA-26-260-03, putting about two years between CVE assignment and this notice to asset owners [14]. Each described entry carries the same remediation line: follow general mitigation factors, and see Hitachi Energy security advisory 8DBD000229 for more information [11]. The CISA text does not name an FCP version that resolves the five CVEs [13].

So the near-term work for a transmission operator is an inventory exercise followed by an access review: which FACTS installations run GWS, and which accounts and which workstations can reach them. Every path CISA describes in detail starts with a credential or with local access to the machine where FCP is installed [6][8]. CISA's summary says an attacker exploiting the vulnerabilities can affect the confidentiality, integrity and availability of the product [17].

What to watch

  • Whether Hitachi Energy advisory 8DBD000229 names an FCP version that resolves the five 2024 CVEs.
  • Whether any of CVE-2024-4872, CVE-2024-3980, CVE-2024-3982, CVE-2024-7940 or CVE-2024-7941 appears in exploitation reporting.
  • Whether other Hitachi Energy products sharing the GWS component draw their own advisory.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories