VORANT. Threat Intelligence Sign in Get the full feed

Hitachi Energy PROMOD V uses insecure HTTP

low vulnerability energy

Hitachi Energy PROMOD V versions 1.0.10 and earlier transmit data over unencrypted HTTP due to a third-party Digipede server limitation, risking credential theft and session hijacking.

CISA republished a Hitachi Energy PSIRT advisory disclosing CVE-2026-10763, affecting PROMOD V versions 1.0.10 and prior. The product relies on insecure HTTP communication instead of HTTPS because the underlying third-party Digipede server does not support HTTPS. This exposes sensitive data in transit to interception or manipulation, which could enable credential theft, session hijacking, or unauthorized access to the system.

Hitachi Energy has released version 1.0.11, which enables HTTPS support on the Digipede server, and recommends administrators follow the updated user guide for configuration steps. No public exploitation has been reported; this is a vendor-disclosed design weakness (CWE-1428) rather than an actively exploited vulnerability. CISA's standard ICS mitigations apply, including network isolation, firewalling control system networks, and avoiding direct internet exposure of these devices.

The affected product is deployed worldwide within the energy sector, per Hitachi Energy's own classification. Given the lack of known exploitation and the availability of a vendor fix, this is a routine patch advisory rather than an urgent, actively targeted threat.

Mentioned in this report

Vulnerabilities CVE-2026-10763

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-02

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free