July 22, 2026

U.S. Issues Cybersecurity Warning for Building Automation Protocol

headline news  ---1 - 2026-07-22T100557.732.jpeg

Flaw can leave certain lighting controls, gateways, and touch panels effectively bricked

 

KNX is not a name most North American lighting people encounter often. It is a building automation standard, popular across Europe for controlling many building technologies including dimming, scene setting, and shading, and largely absent from U.S. specification sheets. That obscurity is part of why a four-year-old vulnerability in the protocol has stayed off most domestic radars, even as federal officials just confirmed the attacks behind it never stopped.

The United States Cybersecurity and Infrastructure Security Agency added CVE-2023-4346 to its Known Exploited Vulnerabilities catalog on July 15, giving federal agencies until July 29 to apply mitigations. The listing was confirmation, years after the flaw first surfaced, that someone is still exploiting it.

The vulnerability lets an attacker with network or even physical access wipe a KNX device's security settings and assign a new access key, locking the legitimate owner out. There is no software patch. The weakness is built into the standard itself, which means every integrator and manufacturer using that authorization method inherits the exposure until the KNX Association addresses it at the protocol level.

ARTICLE CONTINUES BELOW




A Years-Long Campaign, Still Active

For lighting people, the stakes are narrower than the cybersecurity framing suggests, but real. Dimming and scene control sit among KNX's core uses alongside HVAC and shading, so a locked-out device is not an abstraction. Limes Security, the Austrian firm that first flagged the problem, says it was contacted in October 2021 by a German engineering firm that had lost control of a client's building system.

The firm has tracked what it calls the KNXlock campaign since, and reports that scans by Alpha Strike Labs continue to find more than 16,000 potentially vulnerable KNX systems exposed to the internet, concentrated in Germany, Austria, and Switzerland. 

 

What It Means on This Side of the Atlantic

KNX certification lists include touch panels, gateways, and switches from Siemens, Schneider Electric, Johnson Controls, GEWISS, and STEINEL, names familiar to many lighting people. None of that means a specific product is exposed. The flaw depends on how a device's authorization is configured, not on any manufacturer's code. But it shows how far a protocol-level weakness can travel once a standard is this widely built into mainstream hardware.

North American exposure is a fair question. KNX has nowhere near the U.S. specification presence it holds in Europe. But firms working on international portfolios, hospitality groups with European properties, and manufacturers with KNX-certified lines still carry some version of this risk, even when it never shows up in a domestic bid.

The more durable question is what the KNX Association does next. Its guidance still amounts to a checklist: set a key, document it, hand it to the owner. That advice has not closed the gap. It has only told owners how to avoid becoming the next name on Alpha Strike Labs' list.

 

 

 




OTHER NEWS

Company


About Inside Lighting

Contact Us