Hitachi Energy security advisory 8DBD000229 outlines recommended immediate actions. Affected organizations should verify GWS component presence, apply the latest software update from Hitachi Energy, and restrict network access to FCP management interfaces where possible. Deployments without the GWS component are not affected. Follow vendor guidance for patch testing in non-production environments prior to deployment.
Quick answers
What is CVE-2024-3980?
Hitachi Energy security advisory 8DBD000229 outlines recommended immediate actions. Affected organizations should verify GWS component presence, apply the latest software update from Hitachi Energy, and restrict network access to FCP management interfaces where possible. Deployments without the GWS component are not affected. Follow vendor guidance for patch testing in non-production environments prior to deployment.
How severe is CVE-2024-3980?
critical, CVSS 9.9
Is CVE-2024-3980 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2024-3980 be mitigated?
Hitachi Energy security advisory 8DBD000229 outlines recommended immediate actions. Affected organizations should verify GWS component presence, apply the latest software update from Hitachi Energy, and restrict network access to FCP management interfaces where possible. Deployments without the GWS component are not affected. Follow vendor guidance for patch testing in non-production environments prior to deployment.
CVSS
9.9
Vendor
Hitachi Energy
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
FACTS Control Platform (FCP) version 3.4.0, FACTS Control Platform (FCP) version 3.7.0, FACTS Control Platform (FCP) version 3.8.0, FACTS Control Platform (FCP) version 3.10.0, FACTS Control Platform (FCP) version 3.12.0, FACTS Control Platform (FCP) version 3.14.0, FACTS Control Platform (FCP) version 3.15.0, FACTS Control Platform (FCP) version 4.0.0, FACTS Control Platform (FCP) version 4.0.1, FACTS Control Platform (FCP) version 4.1.0, FACTS Control Platform (FCP) version 4.1.1
Mitigation
Hitachi Energy security advisory 8DBD000229 outlines recommended immediate actions. Affected organizations should verify GWS component presence, apply the latest software update from Hitachi Energy, and restrict network access to FCP management interfaces where possible. Deployments without the GWS component are not affected. Follow vendor guidance for patch testing in non-production environments prior to deployment.
Hitachi Energy has disclosed five critical vulnerabilities affecting the FACTS Control Platform (FCP) when the Grid Web Services (GWS) component is present. The flaws, rated CVSS 9.9, encompass improper neutralization of query logic, path traversal, authentication bypass, missing authentication for critical functions, and open redirect. Affected deployments span worldwide energy sector critical infrastructure. No public exploitation has been confirmed, but the severity and industry context demand immediate attention.