CVE-2023-4346: KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability
KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without…
How it works
The weakness is categorized as CWE-645, an overly restrictive account lockout mechanism. In this product class an attacker can trigger repeated failed authorization attempts against the connection authorization process. Because the lockout behavior is overly broad, the mechanism clears device state across the installation and permits the attacker to install a BCU key that prevents further legitimate access.
Am I affected? How to find it in your systems
KNX Protocol implementations are commonly found in building automation, lighting, HVAC, and access-control installations. Inventory all KNX-enabled controllers, interfaces, and gateways on your networks. Confirm whether Connection Authorization Option 1 is in use and whether any additional security options are disabled. Review vendor-supplied configuration exports or device firmware listings; exact version checks and affected configurations must be confirmed against the vendor advisory. Monitor KNX/IP traffic and device logs for repeated authorization failures followed by mass device resets or key changes.
How to remediate
Apply mitigations in accordance with vendor instructions. Verify that any updates or configuration changes meet the requirements of CISA BOD 26-04 for prioritizing security updates based on risk. After applying the vendor update, enable any additional security options that were previously disabled and re-test device authorization behavior.
- Document the current state of every KNX installation before changes.
- Re-apply device keys and authorization settings from a known-good backup after the update.
If you can't patch immediately
Segment KNX networks from general-purpose IT networks and restrict management traffic to authorized hosts only. Disable internet exposure of any KNX/IP gateways where feasible. Increase monitoring of KNX bus and IP traffic for authorization anomalies while the vendor fix is applied. If mitigations cannot be implemented, evaluate discontinuing use of the affected product per CISA guidance.
If your data may have been exposed
Actively exploited vulnerabilities in this class have led to unauthorized device access. Run a free exposure scan of your organization’s email addresses against known breach data to determine whether credentials or device identifiers have already appeared in public records.
AICompiled with AI assistance from public sources and published under our editorial standards.