Insecure HTTP Transmission in Hitachi Energy PROMOD V (CVE‑2026‑10763) Risks Credential Theft
What It Is — Hitachi Energy disclosed that PROMOD V releases ≤ 1.0.10 transmit data over plain HTTP to a third‑party Digipede server. The lack of TLS enables a man‑in‑the‑middle to read or alter traffic.
Exploitability — No public exploit code, but the weakness is trivial to abuse with standard network sniffing tools; CVSS v3 7.1 (High).
Affected Products — Hitachi Energy PROMOD V, versions 1.0.10 and earlier (global deployments in the energy sector).
Why It Matters for Compliance & Audit Readiness
- SOC 2 CC6.1 (Encryption in transit) requires TLS for all sensitive communications; this gap shows a control‑mapping failure.
- Continuous evidence of remediation (upgrade logs, TLS configuration snapshots) is essential to demonstrate due diligence during audits.
- Enterprise buyers increasingly demand proof of secure transmission; a documented fix can be leveraged in a Trust Center audit artifact.
Recommended Actions
- Upgrade PROMOD V to 1.0.11 and enable HTTPS on the Digipede server per the vendor guide.
- Verify TLS termination with a network scan and capture configuration screenshots as audit evidence.
- Map the remediation to SOC 2 CC6.1 and update your control inventory in the continuous‑compliance platform.
Source: CISA Advisory – ICSA‑26‑188‑02