Machine-generated analysis · WAYSCloud LLM
An authentication bypass vulnerability allows unauthenticated querying of system configuration on ABB AWIN Gateways. The advisory notes deployment in critical manufacturing sectors.
Context
ABB AWIN Gateways are industrial control devices used in critical manufacturing environments. The advisory states that successful exploitation could allow remote device reboot or unauthenticated access to sensitive system configuration data. The vulnerability is attributed to improper session validation and missing authentication for critical functions. Fixed firmware versions 2.1-0 for GW100 and 2.0-0 for GW120 are explicitly listed as remediation.
Operator considerations
Check: Inventory all ABB AWIN GW100 rev.2 and GW120 devices for affected firmware versions 2.0-0, 2.0-1, 1.2-0, and 1.2-1
Isolate: Restrict network access to AWIN Gateways from untrusted networks
Patch: Upgrade GW100 rev.2 devices to firmware 2.1-0 (Product ID 3BNP102988R1) and GW120 devices to firmware 2.0-0 (Product ID 3BNP103003R1)
Log: Monitor for unauthorized configuration queries or unexpected device reboots
Successful exploitation of these vulnerabilities could allow an attacker to remotely reboot the device or complete an unauthenticated query to reveal system configuration, including sensitive details.
The following versions of ABB AWIN Gateways are affected:
ABB AWIN Firmware (2.0-0) installed on ABB AWIN GW100 rev.2 2.0-0
ABB AWIN Firmware (2.0-1) installed on ABB AWIN GW100 rev.2 2.0-1
ABB AWIN Firmware (1.2-0) installed on ABB AWIN GW120 1.2-0
ABB AWIN Firmware (1.2-1) installed on ABB AWIN GW120 1.2-1
Vendor
Equipment
ABB
ABB AWIN Gateways
Authentication Bypass by Capture-replay, Missing Authentication for Critical Function
Critical Infrastructure Sectors: Critical Manufacturing
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Switzerland
An unauthenticated query reveals data. Authentication Bypass due to Improper Session Validation.
ABB AWIN G...
Read the full advisory on CISA →