KNX Building Automation Flaw Exploited for Years, CISA Warns
A protocol-level vulnerability allows attackers to lock owners out of lighting controls and other building systems with no software fix available.

Federal Agency Confirms Active Exploitation of Building Protocol Weakness
The U.S. Cybersecurity and Infrastructure Security Agency added a four-year-old building automation vulnerability to its Known Exploited Vulnerabilities catalog on July 15, signaling that attacks targeting the KNX protocol remain active. Federal agencies now have until July 29 to implement mitigations for CVE-2023-4346, a flaw that allows attackers to permanently lock legitimate owners out of their building control systems.
The vulnerability affects KNX, a building automation standard widely deployed across Europe for controlling lighting, HVAC, and shading systems. While KNX has limited presence in North American specifications, the protocol is embedded in products from major manufacturers including Siemens, Schneider Electric, Johnson Controls, GEWISS, and STEINEL.
How the Attack Works
An attacker with network or physical access can exploit the flaw to erase a KNX device's security settings and assign a new access key, effectively bricking the equipment for its rightful owner. The weakness exists within the protocol standard itself rather than in any manufacturer's implementation, meaning no software patch can resolve it. Only the KNX Association can address the issue through changes to the protocol specification.
Austrian security firm Limes Security first documented the problem in October 2021 after a German engineering firm reported losing control of a client's building system. According to Inside Lighting, which first reported the CISA listing, scans by Alpha Strike Labs have identified more than 16,000 potentially vulnerable KNX systems exposed to the internet, primarily concentrated in Germany, Austria, and Switzerland.
Why It Matters
This case illustrates how protocol-level security weaknesses can persist for years across an entire ecosystem of certified products, regardless of individual manufacturers' security practices. For organizations with international building portfolios or manufacturers producing KNX-certified equipment, the vulnerability represents an operational risk that cannot be patched away. When devices lock, hardware replacement is typically the only remedy. The absence of ransom demands distinguishes this campaign from typical extortion attacks, leaving the attackers' motives unclear and making the threat harder to predict or price into risk models.
Limited North American Exposure
KNX specification remains uncommon in U.S. building projects compared to its European market penetration. However, firms managing international property portfolios, hospitality groups with European assets, and manufacturers maintaining KNX product lines carry exposure even when the protocol never appears in domestic bid documents.
The KNX Association's current guidance advises users to set strong authorization keys and document them properly, but this approach has not stopped the ongoing exploitation campaign. Belgian cybersecurity officials report no ransom demands have emerged, and Limes Security notes attackers increasingly use short, easily guessable keys rather than randomized strings.
Inside Lighting first reported the CISA catalog addition and provided details on the vulnerability's impact on lighting control systems.
This is an original analysis by the Omega editorial team. Source reporting: Automation Watch.
Want systems like this working for your business?
Book a Call
