ABB KNX Update Tool

MonitorCVSS 6.4ICS-CERT ICSA-26-209-07Jul 17, 2026
ABBHealthcare
Attack path
Attack VectorAdjacent
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

A vulnerability in the KNX Update Tool (ABB and BJE versions ≤2.0.175) allows an attacker with physical access to the KNX bus to bypass firmware integrity checks and upload modified code to classic KNX devices. This could render devices unusable or cause unintended automation behavior. The vulnerability affects only legacy KNX products that do not support the KNX Secure standard. ABB confirms the issue cannot be resolved through software updates due to fundamental design limitations in the classic KNX protocol stack, which predates modern security standards.

What this means
What could happen
An attacker with physical access to the KNX bus could manipulate device configuration or firmware, potentially rendering classic KNX devices unusable or causing unintended building automation system behavior such as loss of access control or HVAC malfunction.
Who's at risk
Building automation system operators and engineers managing ABB KNX installations, particularly in healthcare facilities, property management, and access control systems. Anyone running legacy KNX products version 2.0.175 or earlier and using the KNX Update Tool to manage device firmware.
How it could be exploited
An attacker gains physical access to the KNX bus (the twisted-pair wiring that connects all devices in the system) and uses the KNX Update Tool to upload modified or malicious firmware to a classic KNX device. The tool does not properly verify the integrity of the firmware being uploaded, allowing the attacker to bypass file signature checks and inject compromised code.
Prerequisites
  • Physical access to the KNX bus wiring
  • Access to a computer with the KNX Update Tool installed
  • Unprivileged user credentials to run the tool or ability to trick an engineer into uploading a malicious file
  • Target device must be a classic (legacy) KNX product, not KNX Secure-compatible
no patch availablerequires physical access (low immediate risk for remote environments)affects building automation and access controllow authentication required to run update tool
Exploitability
Unlikely to be exploited — EPSS score 0.1%
Affected products (2)
2 pending
ProductAffected VersionsFix Status
KNX Update Tool (ABB) <=2.0.175≤ 2.0.175No fix yet
KNX Update Tool (BJE) <=2.0.175≤ 2.0.175No fix yet
Remediation & Mitigation
0/5
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HARDENINGRestrict physical access to KNX bus wiring. Use conduit, cable trays, or secure enclosures to prevent unauthorized tampering with the bus connection.
HARDENINGImplement physical security controls such as locked equipment cabinets and restricted access to areas where KNX devices and buses are installed.
Long-term hardening
0/3
KNX Update Tool (ABB) <=2.0.175
HARDENINGReview and follow ABB's security guidelines for KNX deployments (available in product documentation and References).
All products
HARDENINGDo not use legacy KNX devices to control sensitive functions such as access control systems, door locks, or security-critical automation. Migrate sensitive control functions to KNX Secure-compatible devices where possible.
HARDENINGAudit current deployment of classic KNX devices and identify those controlling sensitive functions. Plan a phased upgrade to KNX Secure products for critical functionality.
API: /api/v1/advisories/b2fb8a5d-6a79-4409-8d87-7b836c44ee77

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

ABB KNX Update Tool | CVSS 6.4 - OTPulse