What it is
CVE-2023-4346 is an unauthenticated vulnerability affecting KNX Association KNX Protocol Connection Authorization Option 1. KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the...
Vulnerability report
KNX Protocol Connection Authorization Option 1
KNX Association / KNX Protocol Connection Authorization Option 1 · 0
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2023-4346 is an unauthenticated vulnerability affecting KNX Association KNX Protocol Connection Authorization Option 1. KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the...
Is it exploited?
Yes. KEV Intelligence tracks this CVE as a known exploited vulnerability. Confidence is confirmed.
Who is affected?
KNX Association / KNX Protocol Connection Authorization Option 1 0.
What should we do?
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
Overview
KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password.
If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX installation, purge all devices without additional security options enabled, and set a BCU key, locking the device. Even if a device is not connected to a network, an attacker with physical access to the device could also exploit this vulnerability in the same way.
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
CISA
Independent exploitation attestation added to the KEV Intelligence record.
Per-source evidence links for KEV attestations are available through the KEV Intelligence Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| All CISA Advisories First | 2026-07-15 12:00 UTC |
| CISA | 2026-07-15 16:42 UTC |
| CVE | 2026-07-15 18:01 UTC |
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Raw values available in Pro and Enterprise.
No scanner integrations recorded yet.
No KEV Intelligence virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →No detection artifacts or sensor request patterns are available for this CVE yet.
Check back as sensor telemetry and scanner integrations are updated.
Risk and context
CVSS v3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
0.9%
Recent mention · All CISA Advisories
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2023-4346 KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism...
Read full advisoryTimeline
Exploitation attested by an external source
Listed in the CISA Known Exploited Vulnerabilities catalog
High-confidence, third-party attested exploitation
Vulnerability disclosed publicly
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2023-4346
Free JSON includes basic KEV fields{
"cve_id": "CVE-2023-4346",
"confidence": "Confirmed",
"cvss_score": 7.5,
"cvss_estimated": false,
"epss_score": 0.00907,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "attempts": 0, "sensors": 0 }
}
Early warning alerts
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.