peter bassill · operator
$ cve CVE-2023-4346 JSON

CVE-2023-4346 KEV

7.5
HIGH · CVSS 3.1 · EPSS 1.3% (pctl 69)

Patch first

On CISA KEV — known exploited in the wild, due 2026-07-29.

Description

KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX installation, purge all devices without additional security options enabled, and set a BCU key, locking the device. Even if a device is not connected to a network, an attacker with physical access to the device could also exploit this vulnerability in the same way.

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS1.29% — more likely to be exploited than 69% of all CVEs
WeaknessCWE-645
On CISA KEVyes — remediate by 2026-07-29
Public exploitnone known
Published2023-08-29
Last modified2026-07-16

CISA KEV

NameKNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability
Added2026-07-15
Due2026-07-29
Vendor / productKNX Association / KNX Protocol Connection Authorization Option 1
Ransomware usenone reported

Affected (1)

VendorProduct
knxconnection authorization

References

→ the Explorer  ·  watch your stack  ·  NVD