Warning: CISA Added Actively Exploited Vulnerability CVE-2023-4346 in KNX Protocol to its KEV Catalogue, Mitigate Immediately!
ID: 03fe3ab1-0b5d-55ec-8d5b-6fdbbdbb35d5
STIX ID: report--03fe3ab1-0b5d-55ec-8d5b-6fdbbdbb35d5
Feed Name: CCB Advisories Feed
Threat Score
The report covers CVE-2023-4346 (“KNXlock”), a vulnerability in KNX building-automation devices that allows attackers to permanently disable devices that were commissioned without a BCU Key by claiming and locking them; active exploitation has been observed against thousands of exposed systems, with remediation in many cases requiring hardware replacement and recommended mitigations including setting BCU Keys, network isolation, and VPN access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
