Hitachi Energy PROMOD V Insecure HTTP Communication Vulnerability
First seen Jul 9, 2026 · Updated Jul 9, 2026 · CVSS 7.1
Hitachi Energy PROMOD V versions 1.0.10 and prior rely on insecure HTTP communication instead of HTTPS due to a lack of TLS support in the third-party Digipede grid server component. This flaw could allow an attacker with network access to intercept or manipulate data in transit, potentially leading to credential theft, session hijacking, or unauthorized access to industrial engineering workstations.
Technical Analysis
CVE-2026-10763 (CVSS v3.1 7.1 High, CVSS v4.0 7.0 High) stems from CWE-1428 (Reliance on HTTP instead of HTTPS) in the Digipede Grid component used by PROMOD V for distributed computing tasks. Because traffic is transmitted in cleartext, an attacker positioned on the network (e.g., via ARP spoofing or a compromised network segment) could perform man-in-the-middle attacks to capture credentials or session tokens, or tamper with data exchanged between PROMOD V clients and the Digipede server, requiring user interaction (UI:R/UI:A) to be exploited. This is a plaintext transport vulnerability rather than a remote code execution flaw, limiting impact primarily to confidentiality and partial integrity rather than full system compromise. There is no direct evidence this affects AI agent frameworks or LLM tool-use pipelines, as PROMOD V is a specialized energy-sector engineering/simulation tool without agentic integration; however, organizations using automation or agent-driven orchestration to manage ICS credentials or telemetry from affected hosts should ensure such integrations do not transmit or cache secrets exposed via this insecure channel.
Affected Systems
Hitachi Energy PROMOD V versions 1.0.10 and prior, specifically the communication channel with the third-party Digipede Grid server used for distributed processing.
Indicators of Compromise
- No specific IOCs (hashes, IPs, domains) published; vulnerability is a design/configuration weakness rather than an active exploited campaign artifact.
Remediation Steps
- 1
Upgrade PROMOD V
Update to PROMOD V version 1.0.11 or later, which supports HTTPS for Digipede server communications.
- 2
Enable HTTPS on Digipede Server
Configure the Digipede Grid server to use HTTPS as described in the 1.0.11 PROMOD V User Guide, Section 2 (Essential Skills -> Running PROMOD V -> Digipede Grid).
- 3
Network Segmentation
Isolate control system networks and PROMOD V hosts behind firewalls, separate from business and internet-facing networks.
- 4
Restrict Remote Access
Use VPNs or other secure remote access methods, kept updated, when remote connectivity to PROMOD V systems is required.
- 5
General ICS Hardening
Apply Hitachi Energy's general mitigation factors and CISA's ICS cybersecurity best practices, including minimizing network exposure and preventing direct internet connectivity for control system devices.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.