# Hitachi Energy FCP flaws affect FACTS Control Platform

Published: 2026-09-17 · Severity: routine · Sectors: energy
Canonical: https://vorant.io/reports/72d844fe-d92c-5e2c-b097-f4b2c24da226/hitachi-energy-fcp-flaws-affect-facts-control-platform

> Five vulnerabilities in Hitachi Energy's FACTS Control Platform with GWS component allow authenticated attackers to inject data, hijack sessions, bypass auth, or phish credentials.

CISA republished a Hitachi Energy PSIRT advisory (8DBD000229) covering five vulnerabilities affecting FACTS Control Platform (FCP) systems that include the GWS component, deployed from 2020 onward. Affected product lines include SVC Light (STATCOM), Fixed Series Capacitor, Thyristor Controlled Series Capacitor, Static Var Compensator, Static Watt Compensator, and Hybrid Synchronous Condensers. FCP versions 3.4.0 through 4.1.1 are impacted depending on the specific CVE; deployments without the GWS component are not affected.

The vulnerabilities span multiple weakness classes: CVE-2024-4872 (query injection into persistent data, requires valid credentials), CVE-2024-3980 (path traversal allowing access/modification of critical system files), CVE-2024-3982 (session hijacking via capture-replay when session logging is enabled, requires local access and admin rights to enable), CVE-2024-7940 (a service intended for local-only access is exposed on all network interfaces without authentication), and CVE-2024-7941 (open redirect enabling phishing/credential theft). No CVSS scores were provided in this excerpt and there is no indication of active exploitation in the wild.

Hitachi Energy and CISA recommend general ICS mitigation practices: minimizing network exposure, isolating control system networks behind firewalls, avoiding direct internet connectivity, using VPNs with the latest updates for remote access, enforcing proper password policies, and following the vendor's Industrial Control Systems Cybersecurity Best Practices. Organizations operating affected FACTS Control Platform deployments with GWS should consult the full Hitachi Energy advisory 8DBD000229 for patch/remediation details and prioritize network segmentation given the exposed unauthenticated service (CVE-2024-7940).

## Mentioned in this report

- Vulnerabilities: CVE-2024-3980, CVE-2024-3982, CVE-2024-4872, CVE-2024-7940, CVE-2024-7941

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-03

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/72d844fe-d92c-5e2c-b097-f4b2c24da226/hitachi-energy-fcp-flaws-affect-facts-control-platform.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
