ABB KNX Update Tool

Summary

ABB has identified a vulnerability in its legacy KNX Update Tool versions that could render the product unusable if exploited. The vulnerability stems from a lack of integrity protection for the firmware image and exclusively affects classic KNX devices not supporting the KNX Secure standard. Exploitation requires physical access to the bus, and ABB has no plans for corrective measures.

IFF Assessment

FOE

This vulnerability allows an attacker with physical access to make a product unusable, directly impacting system availability and security.

Severity

6.4 Medium

Defender Context

This advisory highlights a critical security gap in legacy industrial control systems (ICS) that lack modern security standards like KNX Secure. Defenders should be aware that physical security is paramount for these systems and that patching may not be an option for older devices, necessitating robust network segmentation and access controls.

Read Full Story →