LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-4346: KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 15, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jul 29, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-4346 to its Known Exploited Vulnerabilities catalog on Jul 15, 2026, with a federal patch deadline of Jul 29, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without…

This vulnerability affects KNX Association KNX Protocol Connection Authorization Option 1. It stems from an overly restrictive account lockout mechanism that could allow an attacker to purge all devices without additional security options enabled and set a BCU key to lock the device.

How it works

The weakness is categorized as CWE-645, an overly restrictive account lockout mechanism. In this product class an attacker can trigger repeated failed authorization attempts against the connection authorization process. Because the lockout behavior is overly broad, the mechanism clears device state across the installation and permits the attacker to install a BCU key that prevents further legitimate access.

Am I affected? How to find it in your systems

KNX Protocol implementations are commonly found in building automation, lighting, HVAC, and access-control installations. Inventory all KNX-enabled controllers, interfaces, and gateways on your networks. Confirm whether Connection Authorization Option 1 is in use and whether any additional security options are disabled. Review vendor-supplied configuration exports or device firmware listings; exact version checks and affected configurations must be confirmed against the vendor advisory. Monitor KNX/IP traffic and device logs for repeated authorization failures followed by mass device resets or key changes.

How to remediate

Apply mitigations in accordance with vendor instructions. Verify that any updates or configuration changes meet the requirements of CISA BOD 26-04 for prioritizing security updates based on risk. After applying the vendor update, enable any additional security options that were previously disabled and re-test device authorization behavior.

If you can't patch immediately

Segment KNX networks from general-purpose IT networks and restrict management traffic to authorized hosts only. Disable internet exposure of any KNX/IP gateways where feasible. Increase monitoring of KNX bus and IP traffic for authorization anomalies while the vendor fix is applied. If mitigations cannot be implemented, evaluate discontinuing use of the affected product per CISA guidance.

If your data may have been exposed

Actively exploited vulnerabilities in this class have led to unauthorized device access. Run a free exposure scan of your organization’s email addresses against known breach data to determine whether credentials or device identifiers have already appeared in public records.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedKNX Association · KNX Protocol Connection Authorization Option 1
WeaknessCWE-645
Added to CISA KEVJul 15, 2026
Federal patch deadlineJul 29, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities