ABB KNX Update Tool
A vulnerability in the KNX Update Tool (ABB and BJE versions ≤2.0.175) allows an attacker with physical access to the KNX bus to bypass firmware integrity checks and upload modified code to classic KNX devices. This could render devices unusable or cause unintended automation behavior. The vulnerability affects only legacy KNX products that do not support the KNX Secure standard. ABB confirms the issue cannot be resolved through software updates due to fundamental design limitations in the classic KNX protocol stack, which predates modern security standards.
- Physical access to the KNX bus wiring
- Access to a computer with the KNX Update Tool installed
- Unprivileged user credentials to run the tool or ability to trick an engineer into uploading a malicious file
- Target device must be a classic (legacy) KNX product, not KNX Secure-compatible
Patching may require device reboot — plan for process interruption
/api/v1/advisories/b2fb8a5d-6a79-4409-8d87-7b836c44ee77Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.