The vendor explicitly identifies these products as affected by this CVE.
- ABB AWIN Firmware 2.0-0 installed on ABB AWIN GW100 rev. 2 Product ID: 3BNP102988R1
- ABB AWIN Firmware 2.0-1 installed on ABB AWIN GW100 rev. 2 Product ID: 3BNP102988R1
- ABB AWIN Firmware 1.2-0 installed on ABB AWIN GW120 Product ID 3BNP103003R1
- ABB AWIN Firmware 1.2-1 installed on ABB AWIN GW120 Product ID 3BNP103003R1
- Summary
- An unauthenticated query reveals the system configuration, including sensitive details.
- Remediation
- Do the following actions: - Stop and disconnect any AWIN gateways that are exposed directly to the Internet. - Ensure that physical controls are in place, so no unauthorized personnel can access your devices, components, peripheral equipment, and networks. - Ensure that all AWIN gateways are upgraded to the latest firmware version. Please find the latest version of firmware on the respective product Release Notes. - When remote access is required, only use secure methods. The problem is corrected in the following product versions: - AWIN GW100 rev2: v2.1-0 - AWIN GW120: v2.0-0 ABB recommends that customers contact ABB to obtain the updated firmware as soon as possible. ABB Service Support engineer shall apply the firmware update at earliest convenience.
