CISA republishes advisory on Hitachi Energy FACTS Control Platform vulnerabilities
Organizations using FCP versions with GWS component from 2020 onward must address nine critical CVEs effective immediately

CISA republished a Hitachi Energy PSIRT advisory (PSIRT 8DBD000229) on 2026-09-17 that identifies multiple critical vulnerabilities in the FACTS Control Platform (FCP) when the GWS component is present. The advisory applies to deployments made from 2020 onward and supersedes the initial release dated 2026-07-28.
The notice lists affected FCP versions as 3.4.0, 3.7.0, 3.8.0, 3.10.0, 3.12.0, 3.14.0, 3.15.0, 4.0.0, 4.0.1, 4.1.0, and 4.1.1. Five CVEs are cited: CVE-2024-4872, CVE-2024-3980, CVE-2024-3982, CVE-2024-7940, and CVE-2024-7941, each assigned a CVSS v3 base score of 9.9. Vulnerabilities include improper neutralization of special elements in data query logic, path-traversal, authentication bypass by capture-replay, missing authentication for a critical function, and open-redirect flaws.
Exploitation can compromise confidentiality, integrity, and availability of the product. The advisory notes that an attacker must have valid credentials to exploit CVE-2024-4872, while other flaws may be leveraged without authentication. Systems without the GWS component are not affected. Affected product families include SVC Light (STATCOM), Fixed Series Capacitor, Thyristor Controlled Series Capacitor, Static Var Compensator, Static Watt Compensator, and Hybrid Synchronous Condensers.
Hitachi Energy recommends immediate mitigation actions, including applying vendor patches, restricting network exposure, employing firewalls, and using VPNs for remote access. CISA advises organizations to isolate control-system networks from the Internet, enforce strict password policies, and follow industrial-control-system cybersecurity best practices. Suspected malicious activity should be reported to CISA.
For technical support, organizations should contact Hitachi Energy directly via the contact page listed in the advisory. The notice includes standard legal disclaimers and states that the information is provided "as-is" without warranty.
Further reading


