ELSB/Home Solutions Outdated SW Components in ABB Welcome IP-Gateway.
ABB Welcome IP-Gateway firmware versions 6.20 and earlier contain vulnerabilities in embedded software components. Researchers identified 2,518 CVEs in the firmware image; ABB analysis determined 7 high-severity CVEs with proof-of-concept exploits, 34 medium-severity CVEs without public PoCs, and 403 low-severity CVEs. An attacker with network access to an exposed IP-Gateway could gain unauthorized access and compromise system confidentiality, integrity, and availability. ABB specifies that IP-Gateways should not be directly accessible from the Internet or untrusted networks and should operate behind a firewall with outbound-initiated communication.
- Network access to the IP-Gateway (reachable from attacker's network)
- IP-Gateway is exposed directly to the Internet or an untrusted network
- Device is running vulnerable firmware version 6.20 or earlier
Patching may require device reboot — plan for process interruption
/api/v1/advisories/68c4126e-1280-46aa-93c1-cc8940982979Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.