Executive brief
Hitachi Energy PROMOD V, a software tool used for energy market simulation and planning, uses unencrypted HTTP communication when interacting with third-party Digipede servers. Because the data is not encrypted, an attacker on the same network could intercept or modify sensitive information exchanged between the systems. This could lead to the exposure of proprietary energy modeling data or operational insights.
Technical details
PROMOD V (versions 1.0.0 through 1.0.10) fails to utilize TLS encryption for communications with the integrated 3rd party Digipede server component. This vulnerability is classified as a failure to use a secure communication channel (CWE-319). An attacker with network access between the PROMOD V instance and the Digipede server can perform a man-in-the-middle (MitM) attack to sniff cleartext traffic or inject malicious data. The issue stems from a lack of HTTPS support in the underlying Digipede server integration. While the vendor reports a CVSS 4.0 score of 7.0, user interaction is noted as a requirement for the exploit vector.
Affected products
- Hitachi Energy PROMOD V 1.0.0 to 1.0.10
Timeline
- 2026-06-30: advisory: Initial advisory published by Hitachi Energy and NVD