CVE-2023-4346: KNX Protocol Connection Authorization Option 1 Account Lockout Vulnerability
ID: c27890b3-e407-5cb6-b2c4-b06d1c30a63c
STIX ID: report--c27890b3-e407-5cb6-b2c4-b06d1c30a63c
Feed Name: CosmicBytez Labs
**CVE-2023-4346** is an overly restrictive account lockout vulnerability in KNX Connection Authorization Option 1 that lets an attacker with KNX bus access purge device configurations and set a new BCU key to permanently lock devices; CISA added it to the KEV on 2026-07-15, confirming real-world exploitation, and the report provides technical details, impact assessment, detection indicators, and remediation guidance (enable KNX IP/Data Secure, audit BCU keys, segment KNX traffic).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
