← Vulnerability feed

Vulnerability record · CVE-2023-4346 · published 29 August 2023

CVE-2023-4346: KNX Connection Authorization Option 1 device lockout via BCU key

Knx · Connection Authorization

KNX devices using KNX Connection Authorization with Option 1 can be locked by setting a BCU key, and the device often cannot be reset without entering the current password. An attacker who reaches the KNX installation over the network, or who has physical access, can purge devices lacking additional security options and set a BCU key, denying access to legitimate users.

7.5 CVSS 3.1 High CISA KEV since 15 Jul 2026 EPSS 1.3% · top 30.8% CWE-645 · CWE-645
7.5CVSS 3.1 base score
1.3%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
16 Jul 2026Last modified by NVD

Description

KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX installation, purge all devices without additional security options enabled, and set a BCU key, locking the device. Even if a device is not connected to a network, an attacker with physical access to the device could also exploit this vulnerability in the same way.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw is a remotely reachable, no-authentication denial of service listed in CISA KEV, though EPSS probability is low and no confidentiality or integrity impact exists.

What it is

KNX devices using KNX Connection Authorization with Option 1 can be locked by setting a BCU key, and the device often cannot be reset without entering the current password. An attacker who reaches the KNX installation over the network, or who has physical access, can purge devices lacking additional security options and set a BCU key, denying access to legitimate users.

Impact

The attacker gains no data confidentiality or integrity, but achieves a full denial of service: the device is locked and users cannot reset it to regain access.

Attack surface

Reachable over the network when the device is configured to interface with a network, or via physical access to the device; the CVSS vector shows no privileges or user interaction required.

Exploitation

CVE-2023-4346 is listed in CISA's Known Exploited Vulnerabilities catalog, indicating real-world exploitation, while EPSS is low at roughly 1.3% 30-day probability.

What to do

  • Apply the vendor mitigations referenced in CISA ICS advisory ICSA-23-236-01 and follow CISA BOD 26-04 guidance.
  • If mitigations are unavailable, discontinue use of the affected product or isolate it from untrusted networks.
  • Restrict network access to KNX installations and segment them from general IT and internet-facing networks.
  • Enforce physical access controls on KNX devices and cabinets to prevent on-site exploitation.
  • Inventory KNX devices using Connection Authorization Option 1 and confirm which have additional security options enabled.

Detection

  • Monitor KNX network traffic for device purge or BCU key set operations originating from unexpected hosts.
  • Alert on loss of management access or failed reset attempts reported by KNX devices.
  • Audit physical access logs for KNX cabinets and controllers for unauthorized entry.
  • Track KNX device configuration changes, especially BCU key creation, against approved change records.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-4346 to the Known Exploited Vulnerabilities catalog on 15 July 2026 as "KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 29 July 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-4346 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2023-4346), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.