Hitachi Energy PROMOD V uses insecure HTTP
Hitachi Energy PROMOD V versions 1.0.10 and earlier transmit data over unencrypted HTTP due to a third-party Digipede server limitation, risking credential theft and session hijacking.
CISA republished a Hitachi Energy PSIRT advisory disclosing CVE-2026-10763, affecting PROMOD V versions 1.0.10 and prior. The product relies on insecure HTTP communication instead of HTTPS because the underlying third-party Digipede server does not support HTTPS. This exposes sensitive data in transit to interception or manipulation, which could enable credential theft, session hijacking, or unauthorized access to the system.
Hitachi Energy has released version 1.0.11, which enables HTTPS support on the Digipede server, and recommends administrators follow the updated user guide for configuration steps. No public exploitation has been reported; this is a vendor-disclosed design weakness (CWE-1428) rather than an actively exploited vulnerability. CISA's standard ICS mitigations apply, including network isolation, firewalling control system networks, and avoiding direct internet exposure of these devices.
The affected product is deployed worldwide within the energy sector, per Hitachi Energy's own classification. Given the lack of known exploitation and the availability of a vendor fix, this is a routine patch advisory rather than an urgent, actively targeted threat.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-02
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free