Nowadays, there are a lot of different automation systems to reduce operating costs in modern hotels, business centers, airport or skyscrapers. These automation systems (also known as BMS) are gradually transforming buildings into smart buildings, which may form smart cities. One of the technologies to build smart building is KNX (or KNX/EIB).However, this technology has some vulnerabilities and weaknesses. I will show how an intruder may connect to KNX network in any place and create a springboard to penetrate corporate or industrial network. Moreover, the intruder may destroy all subsystem of BMS. To implement this scenario the intruder just needs to connect to any smart devices. This smart device may be placed in public areas – inside the apartment in hotel or climatic-station located in an unprotected zone. During my presentation I describe the existing methods in KNX which should protect from unauthorized access and demonstrate real situations which can happen in real life: * The weakness in KNX allows an intruder to conduct a DoS attack on any subsystem in KNX and replay attack to manage any node inside KNX network; * There is an opportunity to change configuration in a node (or IP router) without authorization. These actions allow destroying segmentations in KNX network and get access to the entire network; * Finally, in KNX network the intruder may find IP router and update firmware from smart button side via KNX-TP and it will be a springboard for further attack to corporate network.