Executive Summary
CISA published advisory ICSA-26-260-03 disclosing critical vulnerabilities in Hitachi Energy's FACTS Control Platform (FCP) affecting multiple versions from 3.4.0 to 4.1.1 when deployed with the GWS component. The vulnerabilities include SQL injection (CVE-2024-4872), path traversal (CVE-2024-3980), session hijacking (CVE-2024-3982), missing authentication (CVE-2024-7940), and open redirect (CVE-2024-7941) with CVSS scores ranging from 4.3 to 9.9. These flaws could allow authenticated attackers to execute code injection, access critical system files, hijack sessions, and redirect users to malicious sites, potentially compromising the confidentiality, integrity, and availability of critical power grid infrastructure.
This disclosure highlights the growing cybersecurity challenges facing operational technology in the energy sector, particularly as industrial control systems become increasingly connected and targeted by sophisticated threat actors seeking to disrupt critical infrastructure operations.
Why This Matters Now
With energy infrastructure under increasing cyber threat from nation-state actors and the growing convergence of IT and OT systems, these critical vulnerabilities in widely-deployed power grid control systems represent immediate risks to electrical grid stability and national security infrastructure.
Attack Path Analysis
Attackers exploited multiple critical vulnerabilities in Hitachi Energy FACTS Control Platform with GWS component to gain initial access through authentication bypass and unauthenticated services, escalated privileges via SQL injection and path traversal attacks, moved laterally within industrial control networks, established command and control through compromised services, exfiltrated sensitive operational data through unencrypted channels, and ultimately impacted critical power grid infrastructure availability and integrity.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited CVE-2024-7940 (Missing Authentication for Critical Function) to access unauthenticated services exposed on all network interfaces, and CVE-2024-7941 (Open Redirect) for phishing campaigns to steal credentials
Related CVEs
CVE-2024-4872
CVSS 8.8A query validation vulnerability in Hitachi Energy FACTS Control Platform with GWS component allows authenticated attackers to inject code towards persistent data.
Affected Products:
Hitachi Energy FACTS Control Platform (FCP) – 3.4.0, 3.7.0, 3.8.0, 3.10.0, 3.12.0, 3.14.0, 3.15.0, 4.0.0, 4.0.1, 4.1.0, 4.1.1
Exploit Status:
no public exploitCVE-2024-3980
CVSS 8.8Path traversal vulnerability in Hitachi Energy FACTS Control Platform with GWS component allows authenticated users to access or modify system files critical to the application.
Affected Products:
Hitachi Energy FACTS Control Platform (FCP) – 3.4.0, 3.7.0, 3.8.0, 3.10.0, 3.12.0, 3.14.0, 3.15.0, 4.0.0, 4.0.1, 4.1.0, 4.1.1
Exploit Status:
no public exploitCVE-2024-3982
CVSS 8.2Authentication bypass vulnerability in Hitachi Energy FACTS Control Platform with GWS component allows local attackers to exploit session hijacking of established sessions through session logging.
Affected Products:
Hitachi Energy FACTS Control Platform (FCP) – 3.10.0, 3.12.0, 3.14.0, 3.15.0, 4.0.0, 4.0.1, 4.1.0, 4.1.1
Exploit Status:
no public exploitCVE-2024-7940
CVSS 9.8Missing authentication vulnerability in Hitachi Energy FACTS Control Platform with GWS component exposes a local service to all network interfaces without authentication.
Affected Products:
Hitachi Energy FACTS Control Platform (FCP) – 3.14.0, 3.15.0, 4.0.0, 4.0.1, 4.1.0, 4.1.1
Exploit Status:
no public exploitCVE-2024-7941
CVSS 4.3Open redirect vulnerability in Hitachi Energy FACTS Control Platform with GWS component allows attackers to redirect users to malicious sites for phishing attacks.
Affected Products:
Hitachi Energy FACTS Control Platform (FCP) – 3.15.0, 4.1.0, 4.1.1
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Data from Information Repositories: Confluence
Valid Accounts
Abuse Elevation Control Mechanism: Sudo and Sudo Caching
Impair Defenses: Disable or Modify Tools
Network Sniffing
Phishing: Spearphishing Attachment
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Engineering Techniques for Secure Development
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Cybersecurity Program
Control ID: 500.08
DORA – Identification
Control ID: Article 8
CISA ZTMM 2.0 – Authentication and Authorization
Control ID: Identity Pillar
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001:2022 – Use of Cryptography
Control ID: A.8.24
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Oil/Energy/Solar/Greentech
Critical vulnerabilities in Hitachi Energy FACTS Control Platform expose power grid infrastructure to SQL injection, path traversal, and authentication bypass attacks affecting operational technology systems.
Utilities
Electric utility operators face severe risks from compromised FACTS control systems enabling unauthorized access to critical power infrastructure through multiple high-severity CVEs requiring immediate patching.
Industrial Automation
Manufacturing facilities using FACTS power control systems vulnerable to remote code injection and session hijacking attacks that could disrupt industrial processes and compromise system integrity.
Government Administration
Government facilities relying on critical infrastructure power systems face national security implications from unpatched FACTS vulnerabilities enabling potential state-sponsored attacks on essential services.
Sources
- Hitachi Energy FACTS Control Platform (FCP)https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-03Verified
- Hitachi Energy Security Advisory 8DBD000229https://www.hitachienergy.com/contact-us/Verified
- NVD CVE-2024-4872 Detailshttps://nvd.nist.gov/vuln/detail/CVE-2024-4872Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely limit attacker reach across industrial control networks by enforcing identity-aware segmentation and controlled east-west traffic flows. The blast radius of this power grid infrastructure compromise could be significantly reduced through workload isolation and egress policy enforcement.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Zero Trust architecture would likely restrict initial service exposure and limit unauthenticated access to critical FACTS Control Platform components through identity-aware network policies.
Control: Zero Trust Segmentation
Mitigation: Microsegmentation policies would likely limit the scope of elevated privileges by restricting lateral access between control platform components and reducing blast radius of compromised accounts.
Control: East-West Traffic Security
Mitigation: Zero Trust east-west enforcement would likely constrain lateral movement by blocking unauthorized inter-segment communication and reducing attacker reachability across the industrial control network.
Control: Multicloud Visibility & Control
Mitigation: Enhanced visibility and control policies would likely detect and constrain unauthorized communication channels, reducing persistent access to compromised industrial control services.
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely limit data exfiltration by enforcing FQDN filtering and traffic inspection, constraining unauthorized outbound data flows from industrial control systems.
While configuration manipulation may still occur within compromised segments, the overall impact scope would likely be reduced through network isolation and limited blast radius across power grid systems.
Impact at a Glance
Affected Business Functions
- Power Grid Control Systems
- Electrical Grid Stability Management
- FACTS Device Operations
- Energy Infrastructure Monitoring
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of critical infrastructure control system data, authentication credentials, and operational parameters for power grid management systems. Vulnerabilities could allow unauthorized access to FACTS control systems managing electrical grid stability.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with least privilege access controls to prevent lateral movement between industrial control network segments and limit blast radius of compromised credentials
- • Deploy Egress Security & Policy Enforcement with FQDN filtering and data loss prevention to detect and block unauthorized exfiltration of sensitive operational data
- • Enable Encrypted Traffic (HPE) with MACsec/IPsec for all east-west communications between FACTS devices to prevent interception of control system traffic
- • Establish Multicloud Visibility & Control with centralized monitoring to detect anomalous interactions and repeated malformed requests targeting industrial control systems
- • Implement Inline IPS (Suricata) with industrial control system-specific signatures to identify and block known exploit patterns targeting FACTS Control Platform vulnerabilities



