CVE-2026-10763
PROMOD V is using insecure HTTP communication instead of HTTPS. The vulnerability is due to the lack of HTTPS support from 3rd party Digipede server.
Scoring
- Severity
- HIGH
- CVSS base score
- 7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.43%
- CWE
- CWE-1428
- Published
- 2026-06-30
- Last modified
- 2026-06-30
Affected products
- Hitachi Energy PROMOD V
Weakness type
Related vulnerabilities
- CVE-2026-40677 — The use of insecure HTTP transport within AMD optional tools could allow an attacker to conduct a...