ABB KNX Update Tool
Summary
ABB has identified a vulnerability in its legacy KNX Update Tool versions that could render the product unusable if exploited. The vulnerability stems from a lack of integrity protection for the firmware image and exclusively affects classic KNX devices not supporting the KNX Secure standard. Exploitation requires physical access to the bus, and ABB has no plans for corrective measures.
IFF Assessment
This vulnerability allows an attacker with physical access to make a product unusable, directly impacting system availability and security.
Severity
The CVSS score of 6.4 reflects a moderate severity. The 'Missing Support for Integrity Check' vulnerability has a moderate impact and is exploitable with physical access to the bus, limiting its remote attack vector.
Defender Context
This advisory highlights a critical security gap in legacy industrial control systems (ICS) that lack modern security standards like KNX Secure. Defenders should be aware that physical security is paramount for these systems and that patching may not be an option for older devices, necessitating robust network segmentation and access controls.