Impact
The weakness in ABB's KNX Update Tool allows an attacker to bypass the integrity check normally performed on firmware files before installation. This flaw is a failure of cryptographic signature verification, classified as CWE-353. The CVE description does not specify the exact consequences of installing a tampered firmware image, other than that it violates the intended integrity of the device's firmware.
Affected Systems
Products affected are ABB's KNX Update Tool (ABB) and KNX Update Tool (BJE). All released versions up to and including 2.0.175 are affected, as stated in the CVE. Versions beyond 2.0.175 are not referenced in the CVE, so no determination regarding their status can be made from the available data.
Risk and Exploitability
Based on the description, the likely attack vector involves an attacker delivering a forged firmware file to the KNX Update Tool, which then installs the malicious image onto a KNX device. The CVSS score of 5.9 indicates medium severity, and the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in CISA's KEV catalog, indicating no known widespread exploitation. Because the tool is typically operated by administrators with privileged access, the threat appears to be primarily internal, requiring an attacker to have or compromise administrative credentials or access to the update environment.
OpenCVE Enrichment