mediumOther

KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability

First seen Jul 16, 2026 · Updated Jul 16, 2026

icsotbuilding-automationknxaccount-lockoutphysical-securitycisa-kev

CVE-2023-4346 is a vulnerability in the KNX Protocol's Connection Authorization Option 1 mechanism that allows an attacker to exploit an overly restrictive account lockout to purge all devices lacking additional security options and lock devices via a BCU key. This affects building automation and industrial control deployments using KNX, potentially causing denial of service and loss of device control. CISA has added this CVE to its Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild.

Technical Analysis

CVE-2023-4346 stems from a flaw in the account lockout logic of KNX Protocol Connection Authorization Option 1, which fails to adequately restrict repeated or malformed authorization attempts. An attacker leveraging this weakness can trigger a device purge on KNX devices that do not have supplementary security options enabled, and subsequently set a BCU (Bus Coupling Unit) key to lock the device, effectively denying legitimate administrative access. This is primarily a network/physical-proximity attack vector against building management and industrial control systems rather than IT infrastructure. There is no direct or plausible impact to AI agent systems, LLM tool use, or RAG pipelines, as this vulnerability is confined to KNX building automation hardware and protocol-level authorization mechanisms.

Affected Systems

Devices and gateways implementing the KNX Protocol Connection Authorization Option 1 without additional security options enabled, including KNX-compatible building automation controllers, actuators, and BCU (Bus Coupling Unit) hardware.

Indicators of Compromise

  • No specific IOCs published; exploitation involves protocol-level authorization abuse rather than file- or network-based indicators.

Remediation Steps

  1. 1

    Enable Additional Security Options

    Ensure all KNX devices have supplementary security options (e.g., KNX Data Secure or KNX IP Secure) enabled to prevent unauthorized purge and lockout actions.

  2. 2

    Apply Vendor Patches

    Check with KNX Association and device manufacturers for firmware updates or configuration guidance addressing this authorization flaw.

  3. 3

    Restrict Network Access

    Segment and restrict access to KNX bus networks and gateways from untrusted networks and the internet to reduce exposure.

  4. 4

    Monitor for Anomalous Authorization Attempts

    Implement logging and alerting for repeated or failed connection authorization attempts on KNX infrastructure.

  5. 5

    Physical Access Controls

    Limit physical and logical access to KNX bus lines and BCU hardware to authorized personnel only.

CVE / Advisory IDs

CVE-2023-4346

Industries Most Exposed

building automationcritical infrastructurecommercial real estateindustrial control systemssmart facilities

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.