CVE-2023-4346 · Moderate · CISA KEV

KNX Protocol Lockout Mechanism Allows Device Purge and Lockout

Threat Engine Auto-Feed · data current as of 2026-07-15

CVE-2023-4346, listed in CISA KEV, involves an overly restrictive account lockout in KNX Protocol Connection Authorization Option 1. This vulnerability allows an attacker to purge all devices lacking additional security and set a BCU key, effectively locking the device. While no PoC is public, its presence in KEV indicates active exploitation.

  • CVSS:
  • EPSS percentile: 0.38438
  • Exploitation pressure: 48/100 (Moderate)

Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 38th percentile. Threat × Vulnerability from public signals — impact depends on your environment.

Weakness —

This vulnerability stems from an overly restrictive account lockout mechanism. Instead of merely preventing further login attempts after a certain number of failures, the mechanism allows an attacker to trigger a more severe consequence, such as purging device configurations or setting a lockout key, without proper authorization.

Who's at risk

Exposure: unknown · Auth: unknown · unknown

Enterprise profiles most at risk

  • Organizations utilizing KNX Protocol Connection Authorization Option 1, particularly those in critical infrastructure, building management, or industrial control systems.
  • Any enterprise with KNX devices deployed without additional security options enabled.

Misconfigurations that escalate it

  • Failure to enable additional security options on KNX devices.
  • Lack of robust network segmentation for KNX infrastructure.

High-impact scenarios

  • An attacker could purge all device configurations, leading to operational disruption and data loss.
  • An attacker could set a BCU key, effectively locking devices and rendering them inaccessible or inoperable.
  • Compromise of building automation or industrial control systems, potentially impacting physical security or critical processes.

Likely adversaries

  • FIN7 — Financial services (Assessed)
  • LockBit affiliates — Financial services (Assessed)
  • APT38 (Lazarus) — Financial services (Assessed)
  • APT29 (Cozy Bear) — Technology (Assessed)
  • Scattered Spider — Technology (Assessed)

What to do (defensive)

Detect

  • Monitor KNX network traffic for unusual activity, especially failed authentication attempts followed by configuration changes or device lockouts.
  • Regularly audit KNX device configurations to ensure additional security options are enabled.
  • Implement network intrusion detection systems (NIDS) to flag suspicious communication patterns related to KNX devices.

Contain

  • Isolate affected KNX segments from the broader enterprise network.
  • Disable or restrict remote access to KNX devices if not strictly necessary.
  • Review and enforce strict access controls for KNX management interfaces.

Patch

  • Consult KNX Association advisories for patches or firmware updates addressing CVE-2023-4346.
  • Apply all available security updates to KNX Protocol Connection Authorization Option 1 and associated devices.
  • Enable all recommended additional security options on KNX devices.

Frontier verdict — Moderate

Prioritize patching and securing KNX Protocol Connection Authorization Option 1 due to confirmed in-the-wild exploitation and potential for device lockout and data purge.

For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.