PatchSiren cyber security CVE debrief
CVE-2024-41975 ABB CVE debrief
CVE-2024-41975 describes a default-exposure issue in the ABB Automation Builder Gateway for Windows. The gateway listens on all network adapters on TCP port 1217, which can allow remote access in environments where only local access is intended; while user management on the PLCs helps prevent direct access, the advisory notes that unauthenticated attackers may still search for PLCs and map restricted networks.
- Vendor
- ABB
- Product
- Automation Builder
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-24
- Original CVE updated
- 2026-05-12
- Advisory published
- 2026-02-24
- Advisory updated
- 2026-05-12
Who should care
OT/ICS administrators, ABB Automation Builder users, PLC operators, and network/security teams that manage Windows systems exposing the gateway or bundling it with other CODESYS-based installations.
Technical summary
According to the CISA-republished ABB PSIRT advisory, the gateway is a communication channel for clients to AC500 PLCs and is reachable remotely by default because it listens on all adapters on port 1217. If remote access is not required, ABB recommends setting [CmpGwCommDrvTcp] LocalAddress=127.0.0.1 in Gateway.cfg and restarting the gateway. Starting with Automation Builder 2.9.0, the default is changed to local access only.
Defensive priority
Medium
Recommended defensive actions
- Upgrade to ABB Automation Builder 2.9.0 or later, which changes the gateway default to local access only.
- If remote access is not required, set [CmpGwCommDrvTcp] LocalAddress=127.0.0.1 in the Gateway.cfg file and restart the gateway.
- Review systems where the gateway was installed separately or as part of other CODESYS-related setups, and verify their gateway configuration.
- Limit exposure of TCP port 1217 to only the networks that explicitly require it.
- Follow CISA ICS recommended practices and defense-in-depth guidance for OT network segmentation and access control.
Evidence notes
The supplied CISA CSAF advisory (ICSA-26-132-04) states that the gateway listens on all available network adapters on port 1217 by default and can therefore be accessed remotely. It also states that remote access is only required in certain network configurations, that many users may be unaware of this exposure, and that unauthenticated attackers can search for PLCs, though PLC user management prevents direct PLC access unless disabled. The remediation text says to use LocalAddress=127.0.0.1 for local-only access and that Automation Builder 2.9.0 closes the vulnerability by changing the default. The supplied enrichment marks this CVE as not KEV-listed.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-41975 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-41975
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-41975 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-41975
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-132-04.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://psirt.abb.com/csaf/2026/3adr011525.json
Reference
-
Source reference
Unverified legacy reference
URL: https://api-de.codesys.com/fileadmin/user_upload/CODESYS_Group/Ecosystem/Up-to-Date/Security/Security-Advisories/Advisory2025-02_CDS-90834.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-132-04
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.