Critical

ABB KNX Update Tool

All CISA Advisories

Overview

ABB has confirmed a vulnerability in its KNX Update Tool that affects classic KNX devices, which do not support the newer KNX Secure standard. This vulnerability, identified as CVE-2026-12705, allows an attacker with physical access to the device's bus to potentially render it unusable or alter its behavior by tampering with the firmware. ABB has stated that there are no software updates available to address this issue due to the inherent security limitations of legacy KNX devices. Users are advised to limit physical access to these devices and avoid using them for sensitive applications, as there are no plans for corrective measures from ABB. This incident highlights ongoing security challenges with older industrial protocols.

Key Takeaways

  • Affected Systems: ABB KNX Update Tool (versions <=2.0.175), affected classic KNX devices
  • Action Required: ABB recommends following general security guidelines, limiting physical access to devices, and avoiding the use of legacy KNX devices for sensitive functionalities like access control.
  • Timeline: Newly disclosed

Original Article Summary

View CSAF Summary ABB has been contacted by a researcher who identified a vulnerability in one of its products. ABB has been contacted by a researcher who identified a vulnerability in one of its products. The vulnerability report has been shared in responsible disclosure. An attacker who successfully exploited this vulnerability could cause the product to become unusable. ABB confirms the vulnerability but at the same time acknowledges that the issue affects exclusively classic KNX devices that are not supporting the latest KNX Secure standard. Due to a lack of security in legacy KNX devices, the issue cannot be resolved via a software change. In order to actively exploit this vulnerability, an attacker requires physical access to the bus, the affected device is connected to. ABB has no plans of corrective measures. The following versions of ABB KNX Update Tool are affected: KNX Update Tool (ABB) <=2.0.175 (CVE-2026-12705) KNX Update Tool (BJE) <=2.0.175 (CVE-2026-12705) CVSS Vendor Equipment Vulnerabilities v3 6.4 ABB ABB KNX Update Tool Missing Support for Integrity Check Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2026-12705 There is no protection of the integrity of the firmware image. This applies exclusively to legacy KNX products View CVE Details Affected Products ABB KNX Update Tool Vendor: ABB Product Version: KNX Update Tool (ABB) <=2.0.175, KNX Update Tool (BJE) <=2.0.175 Product Status: known_affected Remediations Mitigation Due to the nature of the classic KNX protocol stack and security concept, there are no options to resolve the vulnerability with a software update on a technical level. ABB recommends to follow general security recommendations listed in the security guideline (see References and General security recommendations). In addition, it shall be avoided to control sensitive functionality by legacy KNX devices such as, but not limited to, access control to e.g. hotel rooms or other protected areas. Note: Legacy KNX standards were never designed to meet state of the art security standards like introduced with KNX Data Secure published in 2017. Relevant CWE: CWE-353 Missing Support for Integrity Check Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.4 MEDIUM CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H/E:F/RL:U/RC:C Acknowledgments Qiguang Zhang, Zhen Ling, Junzhou Luo, Chongqing Lei of Southeast University, Xinwen Fu of University of Massachusetts Lowell, and Yue Zhang of Shandong University reported this vulnerability through responsible disclosure. Notice The information in this document is subject to change without notice, and should not be construed as a commitment by ABB. ABB provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall ABB or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if ABB or its suppliers have been advised of the possibility of such damages. This document and parts hereof must not be reproduced or copied without written permission from ABB, and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose. All rights to registrations and trademarks reside with their respective owners. Frequently Asked Questions What causes the vulnerability? - The vulnerability is a result of missing security features which were never specified for ABB legacy KNX products. What is BJE/ABB Firmware-Update 2.0? - The ETS app “ABB Firmware Update 2.0” and “BJE Firmware Update 2.0” is used to update the firmware of various ABB KNX devices directly via the KNX bus. The latest firmware files can be downloaded automatically from the Internet or imported manually. The app can be used with ETS 5 or later. What might an attacker use the vulnerability to do? - An attacker who successfully exploited this vulnerability could cause the affected product to stop working properly if physical access is given to the bus, the product is connected to. In cases the attacker is capable to reverse engineer the firmware of the product, (s)he could change the product behavior. It is a duty of the product and system owner to ensure that physical access to the field bus is limited to authorized personal. How could an attacker exploit the vulnerability? - An attacker could try to exploit the vulnerability by tampering the firmware image or intercept the data flow between the device and the firmware update tool. Could the vulnerability be exploited remotely? - No, to exploit this vulnerability an attacker would need to have physical access to an affected system node. It is assumed that the system is set up in accordance with commonly accepted security practices. Can functional safety be affected by an exploit of this vulnerability? - KNX devices are not in scope of functional safety standards. Why does ABB have no plans for corrective measures? - The security features, that are needed to fix this vulnerability with a perfect technical approach, cannot be delivered with a Software update. When this security advisory was issued, had this vulnerability been publicly disclosed? - No, ABB received information about this vulnerability through responsible disclosure. When this security advisory was issued, had ABB received any reports that this vulnerability was being exploited? - No, ABB had not received any information indicating that this vulnerability had been exploited when this security advisory was originally issued. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Advisory Conversion Disclaimer This ICSA is a verbatim republication of ABB PSIRT 9AKK108472A9270 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact ABB PSIRT directly for any questions regarding this advisory. Revision History Initial Release Date: 2026-07-17 Date Revision Summary 2026-07-17 1 Initial version 2026-07-28 2 Initial CISA Republication of ABB PSIRT 9AKK108472A9270 advisory Legal Notice and Terms of Use

Impact

ABB KNX Update Tool (versions <=2.0.175), affected classic KNX devices

Exploitation Status

No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.

Timeline

Newly disclosed

Remediation

ABB recommends following general security guidelines, limiting physical access to devices, and avoiding the use of legacy KNX devices for sensitive functionalities like access control.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to CVE, Exploit, Vulnerability, and 2 more.

Related Coverage

AI Speeds Up Malware Development, Not Its Success Rate: Analysis

SecurityWeek

A recent analysis by Palo Alto Networks' Unit 42 examined 405 malware samples that are linked to artificial intelligence. The findings revealed that while AI can accelerate the development of malware, it does not necessarily improve its success rate. Out of the analyzed samples, only 12 managed to reach production endpoints, which indicates that most AI-generated malware struggles to effectively infiltrate systems. This study is significant as it suggests that while cybercriminals may adopt AI to create malware more quickly, the effectiveness of these tools remains limited. Companies and security teams should continue to focus on traditional defenses as the majority of AI-linked malware is not successfully deployed.

Aug 26, 2026

Boston Scientific says cyberattack disrupted operations globally

BleepingComputer

Boston Scientific, a medical technology company, recently suffered a cyberattack that disrupted its IT systems, leading to operational issues across its global operations. The attack affected various aspects of the company's services, although specific details about the systems or products impacted were not disclosed. This incident raises concerns about the security of healthcare technology, as disruptions in medical services can have serious implications for patient care. Companies in the healthcare sector need to remain vigilant against such cyber threats, ensuring their systems are secure to protect sensitive patient data and maintain operational integrity.

Aug 26, 2026

FBI disrupts proxy network enabling Chinese espionage operations

BleepingComputer

The FBI has taken action against a proxy network that was facilitating Chinese espionage operations. This network acted as a technical 'quartermaster', providing tools for reconnaissance and management of proxy servers used in cyber spying activities. The disruption aims to dismantle the infrastructure that allowed these operations to flourish, targeting the methods that adversaries used to conceal their actions. This incident is significant as it reflects ongoing efforts to counteract foreign cyber threats and protect sensitive information. It emphasizes the importance of vigilance against cyber espionage tactics that can undermine national security and compromise data integrity.

Aug 26, 2026

Snowflake ends service-account passwords. Now comes the hard part

BleepingComputer

Snowflake has decided to discontinue password authentication for its legacy service accounts, which means organizations will need to switch to passwordless authentication methods. This change aims to enhance security by reducing reliance on passwords, but it poses significant challenges for companies. They must identify what each service account is used for, who manages them, and the level of access each account requires. This process is crucial to ensure that the migration to passwordless systems does not disrupt operations or leave any security gaps. As organizations navigate this transition, they will need to carefully assess their service account configurations and access controls.

Aug 26, 2026

Election official says Tina Peters would be consultant, won’t have access to election systems

CyberScoop

Shasta County's registrar, Clint Curtis, has announced plans to enlist Tina Peters as a consultant for the county's 2026 elections. Despite Peters' past conviction related to election security breaches in Colorado, Curtis expressed confidence in her ability to assist with managing the election process. He emphasized that Peters would not have access to any election systems, aiming to alleviate concerns about potential security risks. This decision has sparked debate, particularly given Peters' controversial history in the election integrity realm. The implications of bringing someone with her background into a role, even without system access, could affect public trust in the electoral process.

Aug 26, 2026

CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing

The Hacker News

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently completed red team assessments on two critical infrastructure organizations, both of which were compromised at the domain level. Despite using similar tactics, only one organization detected the intrusion. This stark difference in defensive outcomes raises concerns about the readiness of critical infrastructure sectors to withstand cyberattacks. The findings emphasize the need for improved security measures and threat detection capabilities within these organizations to better protect against potential breaches that could disrupt essential services. CISA's assessment serves as a crucial reminder of the vulnerabilities that exist within critical infrastructure and the ongoing need for vigilance in cybersecurity practices.

Aug 26, 2026