## Overview
CISA added CVE-2023-4346 to its Known Exploited Vulnerabilities (KEV) list on July 15, 2026. This vulnerability affects KNX devices using the KNX Connection Authorization Option 1. The addition signals a federal deadline for remediation due to evidence of active exploitation.
## Technical Details
The vulnerability stems from an overly restrictive account lockout mechanism. This mechanism can prevent users from resetting their devices if they forget their passwords. The BCU key feature allows users to create a password, but resetting it requires the current password. If an attacker gains access to the network, they can purge all devices and set a BCU key, effectively locking users out. Physical access to the device can also lead to exploitation.
## Impact
The impact of CVE-2023-4346 is significant. An attacker can lock users out of their devices, disrupting operations. This vulnerability is particularly concerning for environments relying on KNX devices for automation and control. Without additional security measures, the risk increases for organizations that do not implement strict access controls.
## Mitigation
To mitigate this vulnerability, organizations should implement strong access controls on KNX devices. Regularly monitor network traffic for suspicious activity. Ensure that all KNX devices are updated with the latest firmware. Consider disabling remote access features if they are not necessary. Training staff on security best practices can also help reduce the risk of exploitation.
CSURFACE Threat Sensor