Executive brief
A vulnerability exists in the KNX protocol, a standard used for building automation and industrial control systems. An attacker with network or physical access can permanently lock building control devices by setting a password (BCU key) that cannot be reset by the legitimate owner. This could lead to a total loss of control over building systems like lighting, HVAC, and security, potentially requiring the physical replacement of hardware to restore operations.
Technical details
The vulnerability is classified as an Overly Restrictive Account Lockout Mechanism (CWE-645) within the KNX Connection Authorization Option 1 implementation. The root cause is the design of the Bus Coupling Unit (BCU) key feature, which allows a password to be set that cannot be reset without the current password. An attacker with network access to the KNX installation can purge all devices that lack additional security options and set a new BCU key. This effectively bricks the device for the legitimate user, as there is no mechanism to override or reset the key once it has been maliciously set. The attack can be performed remotely over a network or via direct physical access to the bus.
Affected products
- KNX Association KNX Protocol Connection Authorization Option 1 All versions supporting Option 1 without additional security options
Timeline
- 2023-08-29: advisory: Initial NVD publication
- 2026-07-15: disclosed: Updated advisory information published