Executive brief
The ABB KNX Update Tool, used for managing and updating smart building automation devices, contains a vulnerability where it fails to properly verify the integrity of data. An attacker with access to the local building network could potentially tamper with device updates or configurations. This could lead to unauthorized changes in building automation behavior or cause devices to become unresponsive, impacting facility operations.
Technical details
The ABB KNX Update Tool (ABB and BJE versions) through 2.0.175 is vulnerable to CWE-353 (Missing Support for Integrity Check). The software fails to implement mechanisms to verify that data has not been altered during transit or storage. An attacker with adjacent network access and low privileges could exploit this during update processes to inject malicious data or cause a denial-of-service condition. The attack complexity is considered high, likely requiring specific timing or man-in-the-middle positioning within the local network segment. ABB has released an advisory (9AKK108472A9270) regarding this issue.
Affected products
- ABB KNX Update Tool (ABB) through 2.0.175
- ABB KNX Update Tool (BJE) through 2.0.175
Timeline
- 2026-07-17: disclosed: Initial publication of CVE-2026-12705
- 2026-07-17: advisory: ABB released security advisory 9AKK108472A9270