Hitachi Energy FACTS Control Platform (FCP)
Hitachi Energy has identified and disclosed vulnerabilities in its FACTS Control Platform (FCP) software, impacting versions from 3.4.0 to 4.1.1. These vulnerabilities, stemming from improper query validation, could allow an authenticated attacker to inject code and potentially gain access to system files, leading to data breaches and system compromise. The vulnerabilities are particularly concerning due to the critical infrastructure sector reliance on this technology. Mitigation involves implementing general security practices and firewall configurations, as well as updating the software to the latest version.
Hitachi Energy has released security advisories detailing vulnerabilities within its FACTS Control Platform (FCP) software. These vulnerabilities affect versions 3.4.0 through 4.1.1 and are linked to the GWS component. A key issue is improper query validation, which can be exploited by an authenticated attacker to inject malicious code. This injection could lead to persistent data access and potential system compromise. The vulnerabilities are particularly relevant given the use of FCP in critical infrastructure sectors, such as energy.
Specifically, the vulnerabilities include:
- **CVE-2024-4872:** Improper query validation allowing code injection.
- **CVE-2024-3980:** Improper query validation allowing code injection.
- **CVE-2024-3982:** Improper query validation allowing code injection.
- **CVE-2024-7940:** Improper query validation allowing code injection.
- **CVE-2024-7941:** Improper query validation allowing code injection.
The vulnerabilities are related to the GWS component and allow an attacker to control or influence file names and paths used in filesystem operations. Successful exploitation requires a valid credential. The affected products include SVC Light (STATCOM), Fixed Series Capacitor, Thyristor Controlled Series Capacitor, Static Var Compensator, and Static Watt Compensator, as well as Hybrid Synchronous Condensers.
Furthermore, the advisory highlights a service exposed by the FACTS Control system with GWS, intended only for local access, but lacking authentication. This exposes the system to potential session hijacking and unauthorized access.
**Impact:** These vulnerabilities could lead to significant data breaches, system compromise, and disruption of critical energy infrastructure. The vulnerabilities are actively being monitored by CISA.
**What to do:** Hitachi Energy recommends implementing general security practices and firewall configurations to minimize the risk of exploitation. This includes limiting network exposure, isolating control systems from business networks, and utilizing secure remote access methods like VPNs. Organizations should update their FCP software to the latest version to address these vulnerabilities. Refer to Hitachi Energy’s security advisory 8DBD000229 for detailed mitigation steps.