Skip to main content
Change Risk Intel

CVE-2023-4346 — KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability

KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security options enabled and set a BCU key to lock the device.

CVSS
6.5 (Medium)
KEV status
CISA KEV — Listed
First seen (CISA KEV)
Recommended change window
Standard change — bundle with the next OT/BMS maintenance window; requires facilities coordination, not IT-only.
Affected products
KNX Association KNX Protocol Connection Authorization Option 1

Why this one matters to a CAB

KNX runs building automation — HVAC, access control, lighting, elevator dispatch — in most modern commercial buildings. This CVE is not an IT vulnerability in the traditional sense; it is an industrial-control-system authorization weakness that lets an attacker on the bus purge devices or install a BCU key that essentially bricks the controller. It was added to KEV in July 2026 even though the original disclosure is from 2023, which is CISA’s way of saying they now have evidence of active abuse.

Defender’s angle

  • Ownership check: KNX is almost always facilities-managed, not IT-managed. The CAB’s first job is to name the accountable facilities engineer and confirm they receive CISA advisories.
  • Network segmentation: KNX/IP traffic should never traverse the corporate LAN. If your KNX IP router is reachable from a user VLAN, that is a bigger finding than the CVE itself.
  • Configuration remediation: the fix is a configuration change, not a firmware update — enable KNX Data Secure or IP Secure on every KNX line coupler, and set a non-default BCU key before handing back to facilities.

What to bring to CAB

An OT/BMS change record — different template than an IT change, because rollback often means physically re-flashing a coupler with a laptop plugged into the bus. Include a facilities engineer on the change record.

Sources

This page summarizes publicly available information from CISA KEV, NVD, and the listed vendor advisory. Change Risk Intel does not publish exploit walkthroughs. Verify with your vendor before scheduling any change window.