KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability
July 31, 2026 · CISA · Severity: CRITICAL
KNX Association's KNX Protocol Connection Authorization Option 1 contains a critical vulnerability (CVE-2023-4346) due to an overly restrictive account lockout mechanism. This flaw enables attackers to purge all devices lacking additional security options and set a BCU key to lock the device, effectively rendering it inaccessible. The vulnerability has been actively exploited in the wild, as noted in CISA's Known Exploited Vulnerabilities catalog, highlighting its immediate threat to users. The KNX Protocol is widely used in building automation systems, meaning this vulnerability could impact organizations and individuals relying on KNX-enabled devices for smart building management. KNX Association, the vendor, has yet to release a patch or mitigation guidance as of July 15, 2026, when CISA added the vulnerability to its catalog. This issue underscores the importance of securing IoT and building automation systems, as exploitation could lead to significant operational disruptions and security risks. Organizations using KNX Protocol devices are urged to monitor for updates and implement additional security measures to mitigate potential attacks.
Key Takeaways
- CVE-2023-4346 is actively exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities catalog.
- The vulnerability involves privilege escalation or authentication bypass, granting unauthorized access to sensitive functions.
- KNX Association KNX Protocol Connection Authorization Option 1: KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security options enabled and set a BCU key to lock the device.