CISA

ABB AWIN Gateways

From Cybersecurity and Infrastructure Security Agency ↗

Successful exploitation of these vulnerabilities could allow an attacker to remotely reboot the device or complete an unauthenticated query to reveal system configuration, including sensitive details.

The following versions of ABB AWIN Gateways are affected:

ABB AWIN Firmware (2.0-0) installed on ABB AWIN GW100 rev.2 2.0-0 

ABB AWIN Firmware (2.0-1) installed on ABB AWIN GW100 rev.2 2.0-1 

ABB AWIN Firmware (1.2-0) installed on ABB AWIN GW120 1.2-0 

ABB AWIN Firmware (1.2-1) installed on ABB AWIN GW120 1.2-1 

Vendor

Equipment

ABB

ABB AWIN Gateways

Authentication Bypass by Capture-replay, Missing Authentication for Critical Function

Critical Infrastructure Sectors: Critical Manufacturing

Countries/Areas Deployed: Worldwide

Company Headquarters Location: Switzerland

An unauthenticated query reveals data. Authentication Bypass due to Improper Session Validation.

ABB AWIN G...