Hitachi Energy PROMOD V
Hitachi Energy has identified an insecure HTTP transmission vulnerability in its PROMOD V product versions. This vulnerability, stemming from a lack of HTTPS support on the Digipede server, could allow attackers to intercept or manipulate sensitive data, potentially leading to credential theft and unauthorized access. The affected versions are PROMOD V versions 1.0.10 and prior, impacting critical infrastructure sectors, particularly energy, worldwide.
Hitachi Energy is addressing a critical vulnerability within its PROMOD V product. The issue arises from the use of insecure HTTP communication instead of HTTPS, a deficiency caused by the Digipede server’s lack of HTTPS support. This allows attackers to potentially intercept data in transit, leading to risks such as credential theft and session hijacking, ultimately compromising system security. The vulnerability is present in PROMOD V versions 1.0.10 and earlier, affecting a wide range of deployments globally, primarily within the energy sector.