🔥 この記事の詳細
2026-09-17 更新
C
月内に

Hitachi EnergyのFACTS Control Platform (FCP) において、GWSコンポーネントを搭載したシステムに脆弱性

脆弱性🌐 英語ソース
📅 2026-09-17📰 cisa
📌 一言でいうと
Hitachi EnergyのFACTS Control Platform (FCP) において、GWSコンポーネントを搭載したシステムに脆弱性が確認されました。この脆弱性が悪用されると、製品の機密性、完全性、および可用性に影響が及ぶ可能性があります。2020年以降に導入された特定の製品群が対象となっており、GWSコンポーネントが含まれない構成は影響を受けません。
🔍該当判定
  • Hitachi Energy製の「FACTS Control Platform (FCP)」を導入している
  • FCPの構成に「GWSコンポーネント」が含まれている
  • SVC Light, Fixed Series Capacitor, Static Var Compensatorなどの電力制御設備を運用している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
影響を受けるFCPバージョン(3.4.0から4.1.1まで)を使用しており、かつGWSコンポーネントが導入されているか確認してください。ベンダーが提供する推奨される即時アクション(緩和策または修正パッチの適用)を速やかに実施してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Hitachi Energy FACTS Control Platform (FCP) 脆弱性対応について

お疲れさまです。Hitachi Energy FCPの脆弱性に関する情報共有です。

■ 概要
FACTS Control Platform (FCP) のGWSコンポーネントにおいて、機密性・完全性・可用性に影響を与える脆弱性が報告されています。

■ 影響範囲
- 対象製品: SVC Light (STATCOM), Fixed Series Capacitor, Thyristor Controlled Series Capacitor, Static Var Compensator, Static Watt Compensator, Hybrid Synchronous Condensers
- 対象バージョン: FCP 3.4.0, 3.7.0, 3.8.0, 3.10.0, 3.12.0, 3.14.0, 3.15.0, 4.0.0, 4.0.1, 4.1.0, 4.1.1
- 条件: GWSコンポーネントが導入されていること(2020年以降の導入分)

■ 対応手順
1. 自社環境のFCPバージョンおよびGWSコンポーネントの有無を確認する
2. 該当する場合、ベンダーが提供する推奨アクション(パッチ適用または緩和策)を適用する

■ 参考情報
- CISA ICS Advisory ICSA-26-260-03

対応優先度: 高
対応期限: 速やかに確認し、適用を検討してください
Subject: [Security Advisory] Hitachi Energy FACTS Control Platform (FCP) Vulnerability

Dear Team,

This is a technical notification regarding vulnerabilities found in the Hitachi Energy FACTS Control Platform (FCP).

■ Overview
Vulnerabilities in the GWS component of FCP could allow an attacker to compromise the confidentiality, integrity, and availability of the affected systems.

■ Scope
- Affected Products: SVC Light (STATCOM), Fixed Series Capacitor, Thyristor Controlled Series Capacitor, Static Var Compensator, Static Watt Compensator, Hybrid Synchronous Condensers
- Affected Versions: FCP 3.4.0, 3.7.0, 3.8.0, 3.10.0, 3.12.0, 3.14.0, 3.15.0, 4.0.0, 4.0.1, 4.1.0, 4.1.1
- Condition: Only applicable if the GWS component is present (deployments from 2020 onwards).

■ Action Plan
1. Verify the installed FCP version and the presence of the GWS component in your environment.
2. If affected, implement the recommended immediate actions/patches provided by the vendor.

■ Reference
- CISA ICS Advisory ICSA-26-260-03

Priority: High
Deadline: Immediate review and remediation recommended.