[KEV] CVE-2023-4346 -- CVSS 0.0 Vulnerability Briefing
[KEV] CVE-2023-4346 | CVSS 0.0 (Low) | Exploit: Operational
What Is It
CVE-2023-4346 is an overly restrictive account lockout mechanism vulnerability in KNX Association's KNX Protocol Connection Authorization Option 1, a building automation and control network protocol component used in industrial and smart building environments.
Technical Detail
The flaw exists in the Connection Authorization Option 1 mechanism of the KNX protocol, where the lockout logic can be abused by an attacker to purge all devices on the network when additional security options are not enabled. An attacker exploiting this condition can also set a BCU (Bus Coupling Unit) key, effectively locking affected devices and rendering them inaccessible to legitimate administrators. The practical impact is a denial-of-service and potential persistent lockout of KNX-connected building automation devices, including HVAC, lighting, and access control systems.
Exploitation Status
CISA has confirmed active exploitation in the wild, with this vulnerability added to the Known Exploited Vulnerabilities catalog on July 15, 2026. The exploit maturity is rated Operational, meaning functional exploit code or techniques capable of reliably triggering the vulnerability exist and are being used in real-world attacks, not merely in controlled research settings.
Who Is Targeting This
No confirmed threat actor attribution is available at this time. Reported attribution data contains no credible vendor, CERT, or CISA KEV reporting that ties this CVE to specific named threat groups or ransomware operations. No specific threat actor origin or motivation has been publicly established.
What To Do
Per CISA's Known Exploited Vulnerabilities binding directive, federal agencies and affected organizations should apply vendor-supplied mitigations or patches by the deadline associated with the July 15, 2026 KEV listing. Organizations using KNX Protocol deployments should immediately verify whether Connection Authorization Option 1 is in use and, where possible, enable additional KNX security options such as Connection Authorization Option 2 or Data Security to reduce exposure. Network segmentation of KNX bus infrastructure from untrusted networks is a critical compensating control. Administrators should audit BCU key configurations across all connected devices to identify any unauthorized key changes that may indicate prior exploitation. Contact KNX Association and device vendors directly for firmware updates or configuration guidance specific to deployed hardware.