← All Advisories

Hitachi Energy PROMOD V Uses Unencrypted HTTP for Digipede Server Communication, Exposing Data to Interception

Last refreshed2026-10-07

Status: UPDATED  |  Advisory ID: CVE-2026-10763

Key Details

CVECVE-2026-10763
CVSS Score / Version7.0 (High) / CVSS v4.0
Updated2026-06-30
Affected productsHitachi Energy PROMOD V
Exploitation prediction (EPSS)0.43% probability of exploitation in the next 30 days (35% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Hitachi EnergyPROMOD V
SubsystemsGeneral OT
SectorsMultiple

What to Know

PROMOD V is using insecure HTTP communication instead of HTTPS. The vulnerability is due to the lack of HTTPS support from 3rd party Digipede server. (NVD)

What to Do

Monitor Hitachi Energy's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-10763
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-10763