Hitachi Energy PROMOD V
Plan PatchCVSS 7.1ICS-CERT ICSA-26-188-02Jun 30, 2026
Hitachi EnergyEnergy
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary
Hitachi Energy PROMOD V versions 1.0.10 and earlier transmit data over unencrypted HTTP. An attacker positioned on the network path could intercept sensitive data, steal credentials or session tokens, and gain unauthorized access to modify system configurations or operational data.
What this means
What could happen
An attacker on the network path between an operator and PROMOD V could intercept unencrypted HTTP traffic, steal login credentials or session tokens, and then access the application to modify energy management configurations or data.
Who's at risk
Energy utility operators and engineers using PROMOD V for energy management and grid operations. Affected versions are 1.0.10 and earlier, commonly deployed in control systems for power distribution and energy monitoring.
How it could be exploited
An attacker positioned on the network (e.g., same subnet, DNS hijack, or BGP interception) intercepts unencrypted HTTP traffic to the PROMOD V server. The attacker captures credentials or session tokens transmitted in cleartext, then uses them to log in and modify system settings or operational data.
Prerequisites
- Network access to HTTP traffic to/from PROMOD V server (e.g., shared network segment, compromised network segment, DNS hijacking, or man-in-the-middle position)
- User must access PROMOD V via HTTP (not HTTPS)
remotely exploitableno authentication required at network layerlow complexityaffects critical energy management software
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (1)
ProductAffected VersionsFix Status
PROMOD V≤ 1.0.101.0.11 and enable HTTPS on Digipede server
Remediation & Mitigation
0/3
Do now
0/2HARDENINGEnable HTTPS on Digipede server as documented in PROMOD V 1.0.11 User Guide, Section 2 Essential Skills > Running PROMOD V > Digipede Grid
HARDENINGRestrict network access to PROMOD V to authorized operator workstations only using firewall rules
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXUpgrade PROMOD V to version 1.0.11 or later
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/c30f8cf3-f053-412c-9c89-2c7211b76ff7Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.