Description
Missing support for integrity check vulnerability in ABB KNX Update Tool (ABB), ABB KNX Update Tool (BJE).

This issue affects KNX Update Tool (ABB): through 2.0.175; KNX Update Tool (BJE): through 2.0.175.
Published: 2026-07-17
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The weakness in ABB's KNX Update Tool allows an attacker to bypass the integrity check normally performed on firmware files before installation. This flaw is a failure of cryptographic signature verification, classified as CWE-353. The CVE description does not specify the exact consequences of installing a tampered firmware image, other than that it violates the intended integrity of the device's firmware.

Affected Systems

Products affected are ABB's KNX Update Tool (ABB) and KNX Update Tool (BJE). All released versions up to and including 2.0.175 are affected, as stated in the CVE. Versions beyond 2.0.175 are not referenced in the CVE, so no determination regarding their status can be made from the available data.

Risk and Exploitability

Based on the description, the likely attack vector involves an attacker delivering a forged firmware file to the KNX Update Tool, which then installs the malicious image onto a KNX device. The CVSS score of 5.9 indicates medium severity, and the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in CISA's KEV catalog, indicating no known widespread exploitation. Because the tool is typically operated by administrators with privileged access, the threat appears to be primarily internal, requiring an attacker to have or compromise administrative credentials or access to the update environment.

Generated by OpenCVE AI on July 31, 2026 at 00:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install the latest ABB KNX Update Tool release that restores integrity verification; if a newer release is unavailable, contact ABB for a patch or advisory.
  • Restrict or disable use of the version known to be vulnerable in production environments until a fix is applied, and enforce the use of alternative, verified firmware update procedures if available.
  • Manually validate firmware signatures before installation by comparing the binary's cryptographic hash against vendor‑provided checksums or trusted repositories, ensuring that only authenticated firmware is flashed onto devices.

Generated by OpenCVE AI on July 31, 2026 at 00:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Abb
Abb knx Update Tool (abb)
Abb knx Update Tool (bje)
Vendors & Products Abb
Abb knx Update Tool (abb)
Abb knx Update Tool (bje)

Fri, 17 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description Missing support for integrity check vulnerability in ABB KNX Update Tool (ABB), ABB KNX Update Tool (BJE). This issue affects KNX Update Tool (ABB): through 2.0.175; KNX Update Tool (BJE): through 2.0.175.
Title Integrity mechanism of KNX-device FW-files can be bypassed in ABB Update Tool
Weaknesses CWE-353
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Abb Knx Update Tool (abb) Knx Update Tool (bje)
cve-icon MITRE

Status: PUBLISHED

Assigner: ABB

Published:

Updated: 2026-07-17T15:25:38.129Z

Reserved: 2026-06-19T10:24:46.696Z

Link: CVE-2026-12705

cve-icon Vulnrichment

Updated: 2026-07-17T15:25:31.450Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T00:30:18Z

Weaknesses
  • CWE-353

    Missing Support for Integrity Check