Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

[KEV] CVE-2023-4346 -- CVSS 0.0 Vulnerability Briefing

[KEV] CVE-2023-4346 | CVSS 0.0 (Low) | Exploit: Operational

What Is It

CVE-2023-4346 is an overly restrictive account lockout mechanism vulnerability in KNX Association's KNX Protocol Connection Authorization Option 1, a building automation protocol component used in smart building and industrial control environments.

Technical Detail

The flaw exists in the Connection Authorization Option 1 implementation of the KNX protocol, where the account lockout mechanism can be abused rather than leveraged as a protective control. An attacker with network access to a KNX installation that lacks additional security options enabled can exploit this condition to purge all devices on the network and set a BCU (Bus Coupling Unit) key, effectively locking devices and denying legitimate access. The practical impact is a denial-of-service condition combined with persistent device lockout, which in building automation contexts can disrupt HVAC, lighting, access control, and other physical systems.

Exploitation Status

The exploit maturity is rated Operational, meaning functional exploit code or techniques capable of reliable exploitation exist and are in active use. CISA has confirmed active exploitation in the wild, with this vulnerability added to the Known Exploited Vulnerabilities catalog on July 15, 2026. Organizations running KNX deployments without supplemental security controls should treat this as an immediate operational risk.

Who Is Targeting This

No specific threat actor attribution at this time. No confirmed or reported threat actors have been publicly linked to exploitation of this vulnerability. Given the nature of the affected technology, building automation and operational technology environments should remain alert to opportunistic targeting.

What To Do

Per CISA's Known Exploited Vulnerabilities binding directive, federal agencies are required to apply mitigations or patches by the deadline associated with the July 15, 2026 KEV listing. All organizations should immediately audit KNX deployments to determine whether Connection Authorization Option 1 is in use without additional security options enabled. Where possible, enable higher-tier KNX security options such as Connection Authorization Option 2 or KNX Data Security to reduce exposure. Network segmentation should be applied to isolate KNX infrastructure from untrusted network segments. Consult KNX Association guidance and device vendor advisories for firmware updates or configuration hardening steps specific to deployed hardware. Monitor for unauthorized BCU key changes or unexpected device resets as indicators of exploitation.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →