
TRC analysis shows ABB Automation Builder Gateway's default configuration exposed industrial PLCs to unauthenticated remote access via CVE-2024-41975. Attackers could enumerate connected controllers and potentially gain unauthorized control if user management was disabled. Runtime segmentation helps contain such OT network compromises. #CloudSecurity 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/icsa-26-132-04
Post summary
The tweet discloses that ABB Automation Builder Gateway’s default settings allow unauthenticated remote access to industrial PLCs through CVE‑2024‑41975, potentially enabling attackers to enumerate and control connected controllers, but it provides no evidence of active exploitation or patching.
