In the ever-evolving landscape of cybersecurity, a quiet yet potent threat has been lurking in the shadows, affecting a critical yet often overlooked aspect of our digital infrastructure: building automation protocols. The recent U.S. Cybersecurity and Infrastructure Security Agency (CISA) warning about CVE-2023-4346, a vulnerability in the KNX building automation protocol, serves as a stark reminder of the interconnectedness of our systems and the potential consequences of overlooked security flaws. This issue, while seemingly niche, has far-reaching implications for anyone involved in building automation, from lighting professionals to manufacturers and international firms.
A Hidden Threat in the Building Automation World
KNX, or KNX Association, is a building automation standard that has gained prominence in Europe for its ability to control various building technologies, including lighting, HVAC, and shading. However, its relative obscurity in North America has kept this vulnerability under the radar for years. The flaw, which allows an attacker to wipe a KNX device's security settings and assign a new access key, effectively locking out the legitimate owner, is not a software bug but an inherent weakness in the protocol itself. This means that every integrator and manufacturer using the KNX authorization method is exposed until the KNX Association addresses the issue at the protocol level.
A Years-Long Campaign, Still Active
The impact of this vulnerability is not just theoretical. Limes Security, the Austrian firm that first flagged the problem, has been tracking the KNXlock campaign since October 2021, when a German engineering firm contacted them about losing control of a client's building system. Since then, scans by Alpha Strike Labs have consistently found over 16,000 potentially vulnerable KNX systems exposed to the internet, primarily in Germany, Austria, and Switzerland. The fix for these devices is typically hardware replacement, and the absence of ransom demands sets this apart from typical extortion attempts.
What It Means on This Side of the Atlantic
While KNX is not a household name in North America, its presence in international portfolios, hospitality groups with European properties, and manufacturers with KNX-certified lines means that this risk is not confined to Europe. North American firms working on international projects or with European clients are potentially exposed, even if they never encounter KNX in their domestic work. This highlights the importance of staying informed about global cybersecurity threats and the interconnectedness of our digital infrastructure.
The KNX Association's Role
The KNX Association's guidance on setting and documenting access keys has not been sufficient to prevent these attacks. It has only served to inform owners of how to avoid becoming the next victim on Alpha Strike Labs' list. The association must take a more proactive approach, addressing the protocol-level weakness that underlies this vulnerability. This could involve reevaluating the authorization method or implementing more robust security measures to protect against these types of attacks.
A Call to Action
The CVE-2023-4346 vulnerability in the KNX building automation protocol is a wake-up call for the entire industry. It underscores the importance of staying vigilant against emerging threats and the need for proactive measures to protect our digital infrastructure. As we continue to digitize and automate our buildings, we must not overlook the security implications of these technologies. The KNX Association has a critical role to play in addressing this issue, and the time to act is now. By doing so, we can ensure that our buildings remain safe and secure, even as they become increasingly interconnected and automated.