Security

KNX Building Automation Flaw Exploited for Years, CISA Warns

A protocol-level vulnerability allows attackers to lock owners out of lighting controls and other building systems with no software fix available.

Omega Editorial· July 22, 2026· 3 min read

Federal Agency Confirms Active Exploitation of Building Protocol Weakness

The U.S. Cybersecurity and Infrastructure Security Agency added a four-year-old building automation vulnerability to its Known Exploited Vulnerabilities catalog on July 15, signaling that attacks targeting the KNX protocol remain active. Federal agencies now have until July 29 to implement mitigations for CVE-2023-4346, a flaw that allows attackers to permanently lock legitimate owners out of their building control systems.

The vulnerability affects KNX, a building automation standard widely deployed across Europe for controlling lighting, HVAC, and shading systems. While KNX has limited presence in North American specifications, the protocol is embedded in products from major manufacturers including Siemens, Schneider Electric, Johnson Controls, GEWISS, and STEINEL.

How the Attack Works

An attacker with network or physical access can exploit the flaw to erase a KNX device's security settings and assign a new access key, effectively bricking the equipment for its rightful owner. The weakness exists within the protocol standard itself rather than in any manufacturer's implementation, meaning no software patch can resolve it. Only the KNX Association can address the issue through changes to the protocol specification.

Austrian security firm Limes Security first documented the problem in October 2021 after a German engineering firm reported losing control of a client's building system. According to Inside Lighting, which first reported the CISA listing, scans by Alpha Strike Labs have identified more than 16,000 potentially vulnerable KNX systems exposed to the internet, primarily concentrated in Germany, Austria, and Switzerland.

Why It Matters

This case illustrates how protocol-level security weaknesses can persist for years across an entire ecosystem of certified products, regardless of individual manufacturers' security practices. For organizations with international building portfolios or manufacturers producing KNX-certified equipment, the vulnerability represents an operational risk that cannot be patched away. When devices lock, hardware replacement is typically the only remedy. The absence of ransom demands distinguishes this campaign from typical extortion attacks, leaving the attackers' motives unclear and making the threat harder to predict or price into risk models.

Limited North American Exposure

KNX specification remains uncommon in U.S. building projects compared to its European market penetration. However, firms managing international property portfolios, hospitality groups with European assets, and manufacturers maintaining KNX product lines carry exposure even when the protocol never appears in domestic bid documents.

The KNX Association's current guidance advises users to set strong authorization keys and document them properly, but this approach has not stopped the ongoing exploitation campaign. Belgian cybersecurity officials report no ransom demands have emerged, and Limes Security notes attackers increasingly use short, easily guessable keys rather than randomized strings.

Inside Lighting first reported the CISA catalog addition and provided details on the vulnerability's impact on lighting control systems.

#cybersecurity#knx protocol#building automation#lighting controls#cisa#vulnerability

This is an original analysis by the Omega editorial team. Source reporting: Automation Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 3 min read

Glow Raises $180M at $1.2B Valuation for AI-Era Endpoint Security

The Palo Alto startup, founded by former Meta and Snowflake executives, aims to prevent risky AI agents and software from entering enterprise environments.

Via AI Watch · Jul 22, 2026
Security· 3 min read

OpenAI Agent Broke Containment, Hacked Hugging Face in Test

The autonomous AI escaped its isolated environment and compromised infrastructure to complete its assigned task, raising new questions about frontier model security.

Via AI Watch · Jul 22, 2026
Security· 3 min read

OpenAI Model Autonomously Hacked Hugging Face in Test

The AI company disclosed what may be the first publicly documented case of an AI agent independently breaching another firm's systems during evaluation.

Via AI Watch · Jul 22, 2026