PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-41975 ABB CVE debrief

CVE-2024-41975 describes a default-exposure issue in the ABB Automation Builder Gateway for Windows. The gateway listens on all network adapters on TCP port 1217, which can allow remote access in environments where only local access is intended; while user management on the PLCs helps prevent direct access, the advisory notes that unauthenticated attackers may still search for PLCs and map restricted networks.

Vendor
ABB
Product
Automation Builder
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-02-24
Original CVE updated
2026-05-12
Advisory published
2026-02-24
Advisory updated
2026-05-12

Who should care

OT/ICS administrators, ABB Automation Builder users, PLC operators, and network/security teams that manage Windows systems exposing the gateway or bundling it with other CODESYS-based installations.

Technical summary

According to the CISA-republished ABB PSIRT advisory, the gateway is a communication channel for clients to AC500 PLCs and is reachable remotely by default because it listens on all adapters on port 1217. If remote access is not required, ABB recommends setting [CmpGwCommDrvTcp] LocalAddress=127.0.0.1 in Gateway.cfg and restarting the gateway. Starting with Automation Builder 2.9.0, the default is changed to local access only.

Defensive priority

Medium

Recommended defensive actions

  • Upgrade to ABB Automation Builder 2.9.0 or later, which changes the gateway default to local access only.
  • If remote access is not required, set [CmpGwCommDrvTcp] LocalAddress=127.0.0.1 in the Gateway.cfg file and restart the gateway.
  • Review systems where the gateway was installed separately or as part of other CODESYS-related setups, and verify their gateway configuration.
  • Limit exposure of TCP port 1217 to only the networks that explicitly require it.
  • Follow CISA ICS recommended practices and defense-in-depth guidance for OT network segmentation and access control.

Evidence notes

The supplied CISA CSAF advisory (ICSA-26-132-04) states that the gateway listens on all available network adapters on port 1217 by default and can therefore be accessed remotely. It also states that remote access is only required in certain network configurations, that many users may be unaware of this exposure, and that unauthenticated attackers can search for PLCs, though PLC user management prevents direct PLC access unless disabled. The remediation text says to use LocalAddress=127.0.0.1 for local-only access and that Automation Builder 2.9.0 closes the vulnerability by changing the default. The supplied enrichment marks this CVE as not KEV-listed.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-41975 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-41975

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-41975 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-41975

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-132-04.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://psirt.abb.com/csaf/2026/3adr011525.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://api-de.codesys.com/fileadmin/user_upload/CODESYS_Group/Ecosystem/Up-to-Date/Security/Security-Advisories/Advisory2025-02_CDS-90834.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-132-04

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.