CVE-2025-13777

8.3

ABB · AWIN GW100 and AWIN GW120

An authentication bypass vulnerability exists in ABB AWIN gateway devices due to a capture-replay flaw, allowing unauthenticated attackers to potentially disrupt services.

Executive summary

A critical authentication bypass vulnerability in ABB AWIN gateway devices allows unauthenticated attackers to intercept and replay credentials, posing a significant risk to industrial control systems.

Vulnerability

This vulnerability is identified as a capture-replay flaw (CWE-294), where an unauthenticated attacker can capture valid authentication traffic and replay it to gain unauthorized access to the gateway.

Business impact

The exploitation of this vulnerability could lead to significant operational disruption, as the attacker gains unauthorized control over the affected industrial gateway. Given the CVSS score of 8.3, this represents a high-severity risk that could result in loss of availability or unauthorized configuration changes within the production environment.

Remediation

Immediate Action: Review the official ABB security advisory for available firmware updates or configuration hardening steps to mitigate the replay attack vector.

Proactive Monitoring: Monitor network traffic for unusual authentication patterns or repeated connection attempts originating from the same source to the gateway management interface.

Compensating Controls: Implement strict network segmentation to ensure that the gateway management interfaces are not exposed to untrusted network segments, thereby limiting the attacker's ability to capture traffic.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability presents a high risk to availability and control integrity for the affected ABB hardware. Organizations should prioritize identifying all instances of the impacted models within their infrastructure and apply vendor-provided updates immediately upon release. Until patches are applied, ensure that access to these devices is strictly restricted to authorized management subnets to minimize exposure.

More ABB CVEs

Sources