{"api_version":"v1","generated_at":"2026-10-08T09:05:00+00:00","product":{"cve_count":1,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-codesys-codesys-edge-gateway-b8227a292400","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"CODESYS Edge Gateway","next_cursor":null,"observations":[{"affected":"< 3.5.21.0","affected_versions_present":true,"cve_id":"CVE-2024-41975","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-41975","fixed":"If remote access is not required, check the \"LocalAddress\" setting in the [CmpGwCommDrvTcp] section of the Gateway's configuration file as follows (restart of gateway required in case of changes): [CmpGwCommDrvTcp] LocalAddress=127.0.0.1 ; allow access only from the local computer The gateway configuration file can be located at (example for Automation Builder 2.8): %ProgramFiles%\\ABB\\AB2.8\\AutomationBuilder\\GatewayPLC\\Gateway.cfg Starting with Automation Builder version 2.9.0 the vulnerability is closed by setting the default for the gateway to local access. Automation Builder 2.9.0 is available for download from the related download site. https://www.abb.com/global/en/areas/motion/digital-tools/automation-builder/software-download","last_modified":"2025-03-18T13:09:09.855Z","patch_url":"https://search.abb.com/library/Download.aspx?DocumentID=3ADR011525&LanguageCode=en&DocumentPartId=&Action=Launch","primary_source":"","published":"2025-03-18T11:04:26.013Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"CODESYS"}}
