CVE-2023-4346
KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability
Description
CVE-2023-4346 is a high-severity vulnerability in KNX devices using KNX Connection Authorization Option 1 that allows an attacker to permanently lock devices, causing a denial of service that legitimate users cannot recover from. The flaw stems from an overly restrictive account lockout mechanism: the BCU key feature lets anyone set a device password, but that password often cannot be reset without knowing the current one. An attacker with network access to a KNX installation can purge all devices that have no additional security options enabled and set their own BCU key, effectively locking owners out of their building automation devices; the same attack works with physical access. Because CISA has added CVE-2023-4346 to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild, organizations running KNX Connection Authorization should treat remediation as urgent.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HOpen in CalculatorCWEs
Affected Products
| Vendor | Product | Version |
|---|---|---|
| knx | connection authorization | - |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01(Third Party Advisory, US Government Resource)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-4346(US Government Resource)
Weakness Type
CWE-645: Overly Restrictive Account Lockout Mechanism
An overly restrictive account lockout mechanism allows attackers to deliberately lock out legitimate users and cause a targeted denial of service. In KNX devices supporting Connection Authorization Option 1, this weakness manifests through the BCU key feature: an attacker can set a password that legitimate operators cannot reset without the current password, permanently locking them out of their own devices.
Learn more: CWE-645 — Overly Restrictive Account Lockout Mechanism
Impact Analysis
CVE-2023-4346 carries a CVSS 3.1 score of 7.5 (High) and is remotely exploitable without physical access when the KNX installation is reachable over a network — the attack is easy to exploit with no special conditions, requires no authentication, and needs no user action. The impact is concentrated entirely on availability, which is rated High: an attacker can lock KNX building automation devices with their own BCU key, and because the password often cannot be reset without knowing the current one, affected devices may be rendered permanently inaccessible to their owners. Confidentiality and integrity are not directly affected, but a lasting loss of control over building automation infrastructure can translate into significant operational disruption. The vulnerability is also exploitable through physical access to unconnected devices, widening the exposure beyond networked installations. Its inclusion in CISA's KEV catalog confirms that this is not a theoretical risk but an actively exploited security issue.
Exploit Maturity
CISA has confirmed active exploitation of CVE-2023-4346 in the wild by adding it to the Known Exploited Vulnerabilities catalog, with a remediation due date of 2026-07-29; use in ransomware campaigns is currently unknown. No public exploit code is referenced in the available advisories — the listed references are the CISA ICS advisory ICSA-23-236-01 and the KEV catalog entry. The EPSS score of about 0.9% (54th percentile) suggests exploitation is not widespread across the internet, but the KEV listing means real-world attacks against KNX installations have occurred, so exposed KNX deployments should be mitigated without delay.
Remediation
- Follow the CISA KEV required action: apply mitigations in accordance with vendor instructions, ensure compliance with CISA's BOD 26-04 "Prioritizing Security Updates Based on Risk" guidance and CISA's Forensics Triage Requirements, and discontinue use of the product if mitigations are unavailable. The KEV remediation due date is 2026-07-29.
- Review the guidance in CISA advisory ICSA-23-236-01 for KNX Protocol Connection Authorization Option 1 and evaluate each KNX asset's internet and network exposure, as required by BOD 26-04.
- As an interim mitigation, isolate KNX installations from untrusted networks: remove direct internet exposure, segment the building automation network, and restrict access to KNX interfaces to authorized management hosts only.
- Enable all additional security options available on your KNX devices so they cannot be purged and re-keyed by an unauthenticated party, and protect physical access to devices, since the attack also works locally.
- Monitor KNX installations for unexpected device purges or BCU key changes, and establish a documented recovery and escalation process in case devices become locked. Longer term, prefer lockout designs that allow secondary verification for unlock instead of unrecoverable hard lockouts, in line with CWE-645 mitigation practice.
Technical Details
The vulnerability lies in how KNX Connection Authorization Option 1 implements device password protection via the BCU key. Setting a BCU key is possible for any party that can interface with the KNX installation, while resetting it typically requires knowledge of the current key — an overly restrictive lockout design (CWE-645) that turns the protection feature itself into a denial-of-service primitive. In a network-facing installation, an attacker interfaces with the KNX bus, purges all devices that have no additional security options enabled, and writes an attacker-chosen BCU key, after which legitimate users can no longer authenticate to or reset their devices; the same sequence is possible with physical access to an unconnected device. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) reflects this precisely: network attack vector, low complexity, no privileges or user interaction required, with the impact scoped to a complete loss of availability of the affected KNX devices.
Frequently Asked Questions
Is CVE-2023-4346 being actively exploited?
Yes. CISA has added CVE-2023-4346 to its Known Exploited Vulnerabilities catalog, which confirms active exploitation in the wild, with a remediation due date of 2026-07-29. The EPSS score of roughly 0.9% indicates exploitation is not yet widespread, and any use in ransomware campaigns is currently unknown.
What products are affected by CVE-2023-4346?
The vulnerability affects KNX devices that use KNX Connection Authorization and support Option 1, as implemented via the BCU key feature. The CISA KEV catalog lists the affected product as KNX Protocol Connection Authorization Option 1 from the KNX Association, and exposure depends on the specific device implementation.
How do I fix CVE-2023-4346?
Apply mitigations according to vendor instructions and the CISA advisory ICSA-23-236-01, and discontinue use of the product if no mitigations are available. In the interim, remove KNX installations from untrusted networks, enable all additional security options on devices, and restrict both network and physical access to the installation.
How severe is CVE-2023-4346?
CVE-2023-4346 is rated High with a CVSS 3.1 score of 7.5. It can be exploited remotely without authentication or user interaction and results in a complete loss of device availability, potentially locking owners out of their KNX devices permanently. Its EPSS score sits around the 54th percentile, but the confirmed active exploitation makes it a priority issue for KNX operators.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.