{"schema_version":1,"title":"Hitachi Energy vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 10 vulnerabilities in Hitachi Energy: 0 in the last 7 days and 6 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2024-4872, was published on 17 September 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/hitachi-energy","json_url":"https://junglewise.ai/threats/vendors/hitachi-energy.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/hitachi-energy","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":6,"all_time":10,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":5,"last_90_days":6,"last_365_days":8},"latest":[{"cve":"CVE-2024-4872","cvss":9.9,"slug":"cve-2024-4872-hitachi-energy-facts-control-platform-multiple-vulnerabilities-in","title":"Hitachi Energy FACTS Control Platform multiple vulnerabilities in GWS component","severity":"high","exploited":false,"published_at":"2026-09-17T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-4872-hitachi-energy-facts-control-platform-multiple-vulnerabilities-in"},{"cve":"CVE-2026-9854","cvss":7.8,"epss":0.0014,"slug":"cve-2026-9854-hitachi-energy-sys600-privilege-escalation-in-rbac-mechanism","title":"Hitachi Energy SYS600 privilege escalation in RBAC mechanism","severity":"high","exploited":false,"published_at":"2026-09-03T13:06:26.083+00:00","url":"https://junglewise.ai/threats/cve-2026-9854-hitachi-energy-sys600-privilege-escalation-in-rbac-mechanism"},{"cve":"CVE-2026-9853","cvss":7.8,"epss":0.0014,"slug":"cve-2026-9853-hitachi-energy-sys600-unauthorized-access-to-application-objects","title":"Hitachi Energy SYS600 unauthorized access to application objects","severity":"high","exploited":false,"published_at":"2026-09-03T13:06:25.943+00:00","url":"https://junglewise.ai/threats/cve-2026-9853-hitachi-energy-sys600-unauthorized-access-to-application-objects"},{"cve":"CVE-2026-9852","cvss":7.8,"epss":0.0021,"slug":"cve-2026-9852-hitachi-energy-sys600-csv-injection-in-logs","title":"Hitachi Energy SYS600 CSV injection in logs","severity":"high","exploited":false,"published_at":"2026-09-03T13:06:25.803+00:00","url":"https://junglewise.ai/threats/cve-2026-9852-hitachi-energy-sys600-csv-injection-in-logs"},{"cve":"CVE-2026-17539","cvss":5.9,"epss":0.0027,"slug":"cve-2026-17539-hitachi-energy-rtu500-null-pointer-dereference-in-iec-104","title":"Hitachi Energy RTU500 NULL pointer dereference in IEC 104 messaging","severity":"medium","exploited":false,"published_at":"2026-09-03T13:04:35.693+00:00","url":"https://junglewise.ai/threats/cve-2026-17539-hitachi-energy-rtu500-null-pointer-dereference-in-iec-104"},{"cve":"CVE-2026-10763","cvss":7,"slug":"cve-2026-10763-hitachi-energy-promod-v-use-of-unencrypted-http-in-digipede","title":"Hitachi Energy PROMOD V use of unencrypted HTTP in Digipede communication","severity":"info","exploited":false,"published_at":"2026-06-30T10:16:34.067+00:00","url":"https://junglewise.ai/threats/cve-2026-10763-hitachi-energy-promod-v-use-of-unencrypted-http-in-digipede"},{"cve":"CVE-2026-8479","cvss":6.9,"slug":"cve-2026-8479-hitachi-energy-iec-60870-5-104-null-pointer-dereference-dos","title":"Hitachi Energy IEC 60870-5-104 NULL pointer dereference DoS","severity":"info","exploited":false,"published_at":"2026-05-26T14:16:41.247+00:00","url":"https://junglewise.ai/threats/cve-2026-8479-hitachi-energy-iec-60870-5-104-null-pointer-dereference-dos"},{"cve":"CVE-2026-7310","cvss":4.4,"slug":"cve-2026-7310-hitachi-energy-hidraw-heap-overflow-in-xml-parser","title":"Hitachi Energy HiDraw heap overflow in XML parser","severity":"info","exploited":false,"published_at":"2026-05-26T14:16:40.523+00:00","url":"https://junglewise.ai/threats/cve-2026-7310-hitachi-energy-hidraw-heap-overflow-in-xml-parser"},{"cve":"CVE-2022-4304","cvss":3.1,"epss":0.162,"slug":"cve-2022-4304-hitachi-energy-gms600-observable-discrepancy-in-openssl-rsa","title":"RUSTSEC-2023-0007 - Timing Oracle in RSA Decryption","severity":"high","exploited":false,"published_at":"2023-02-07T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-4304-hitachi-energy-gms600-observable-discrepancy-in-openssl-rsa"},{"cve":"CVE-2018-1002208","cvss":3.1,"epss":0.0988,"slug":"cve-2018-1002208-abb-pcm600","title":"Improper Limitation of a Pathname to a Restricted Directory in SharpZipLib","severity":"high","exploited":false,"published_at":"2022-05-13T01:35:03+00:00","url":"https://junglewise.ai/threats/cve-2018-1002208-abb-pcm600"}],"vendor":{"hub":true,"name":"Hitachi Energy","slug":"hitachi-energy","homepage":"https://www.hitachienergy.com/","description":"Hitachi Energy is a global provider of power systems and electrical infrastructure solutions.","url":"https://junglewise.ai/threats/vendors/hitachi-energy"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2024-4872","cvss":9.9,"slug":"cve-2024-4872-hitachi-energy-facts-control-platform-multiple-vulnerabilities-in","title":"Hitachi Energy FACTS Control Platform multiple vulnerabilities in GWS component","severity":"high","exploited":false,"published_at":"2026-09-17T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-4872-hitachi-energy-facts-control-platform-multiple-vulnerabilities-in"},{"cve":"CVE-2026-9852","cvss":7.8,"epss":0.0021,"slug":"cve-2026-9852-hitachi-energy-sys600-csv-injection-in-logs","title":"Hitachi Energy SYS600 CSV injection in logs","severity":"high","exploited":false,"published_at":"2026-09-03T13:06:25.803+00:00","url":"https://junglewise.ai/threats/cve-2026-9852-hitachi-energy-sys600-csv-injection-in-logs"},{"cve":"CVE-2026-9854","cvss":7.8,"epss":0.0014,"slug":"cve-2026-9854-hitachi-energy-sys600-privilege-escalation-in-rbac-mechanism","title":"Hitachi Energy SYS600 privilege escalation in RBAC mechanism","severity":"high","exploited":false,"published_at":"2026-09-03T13:06:26.083+00:00","url":"https://junglewise.ai/threats/cve-2026-9854-hitachi-energy-sys600-privilege-escalation-in-rbac-mechanism"},{"cve":"CVE-2026-9853","cvss":7.8,"epss":0.0014,"slug":"cve-2026-9853-hitachi-energy-sys600-unauthorized-access-to-application-objects","title":"Hitachi Energy SYS600 unauthorized access to application objects","severity":"high","exploited":false,"published_at":"2026-09-03T13:06:25.943+00:00","url":"https://junglewise.ai/threats/cve-2026-9853-hitachi-energy-sys600-unauthorized-access-to-application-objects"},{"cve":"CVE-2022-4304","cvss":3.1,"epss":0.162,"slug":"cve-2022-4304-hitachi-energy-gms600-observable-discrepancy-in-openssl-rsa","title":"RUSTSEC-2023-0007 - Timing Oracle in RSA Decryption","severity":"high","exploited":false,"published_at":"2023-02-07T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-4304-hitachi-energy-gms600-observable-discrepancy-in-openssl-rsa"},{"cve":"CVE-2018-1002208","cvss":3.1,"epss":0.0988,"slug":"cve-2018-1002208-abb-pcm600","title":"Improper Limitation of a Pathname to a Restricted Directory in SharpZipLib","severity":"high","exploited":false,"published_at":"2022-05-13T01:35:03+00:00","url":"https://junglewise.ai/threats/cve-2018-1002208-abb-pcm600"},{"cve":"CVE-2026-17539","cvss":5.9,"epss":0.0027,"slug":"cve-2026-17539-hitachi-energy-rtu500-null-pointer-dereference-in-iec-104","title":"Hitachi Energy RTU500 NULL pointer dereference in IEC 104 messaging","severity":"medium","exploited":false,"published_at":"2026-09-03T13:04:35.693+00:00","url":"https://junglewise.ai/threats/cve-2026-17539-hitachi-energy-rtu500-null-pointer-dereference-in-iec-104"},{"cve":"CVE-2026-10763","cvss":7,"slug":"cve-2026-10763-hitachi-energy-promod-v-use-of-unencrypted-http-in-digipede","title":"Hitachi Energy PROMOD V use of unencrypted HTTP in Digipede communication","severity":"info","exploited":false,"published_at":"2026-06-30T10:16:34.067+00:00","url":"https://junglewise.ai/threats/cve-2026-10763-hitachi-energy-promod-v-use-of-unencrypted-http-in-digipede"},{"cve":"CVE-2026-8479","cvss":6.9,"slug":"cve-2026-8479-hitachi-energy-iec-60870-5-104-null-pointer-dereference-dos","title":"Hitachi Energy IEC 60870-5-104 NULL pointer dereference DoS","severity":"info","exploited":false,"published_at":"2026-05-26T14:16:41.247+00:00","url":"https://junglewise.ai/threats/cve-2026-8479-hitachi-energy-iec-60870-5-104-null-pointer-dereference-dos"},{"cve":"CVE-2026-7310","cvss":4.4,"slug":"cve-2026-7310-hitachi-energy-hidraw-heap-overflow-in-xml-parser","title":"Hitachi Energy HiDraw heap overflow in XML parser","severity":"info","exploited":false,"published_at":"2026-05-26T14:16:40.523+00:00","url":"https://junglewise.ai/threats/cve-2026-7310-hitachi-energy-hidraw-heap-overflow-in-xml-parser"}],"generated_at":"2026-09-26T20:07:00.238639+00:00","technologies":[{"name":"Hitachi Energy SYS600","slug":"sys600","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/sys600"}]}