High (7.5) Actively Exploited

KNX devices locked via BCU key exploit (CVE-2023-4346)

CVE-2023-4346

Actively exploited - CVE-2023-4346 allows attackers on the network to lock KNX devices by setting a BCU key password. CISA KEV confirmed. Apply mitigations immediately.

Affected: Knx Connection Authorization

Actively exploited in the wild - CVE-2023-4346 is a high-severity vulnerability in KNX devices using Connection Authorization Option 1 that lets network attackers lock devices by setting a BCU key password, preventing legitimate access. CISA has confirmed active exploitation; no vendor patch is available yet.

Overview

CVE-2023-4346 affects KNX devices that implement KNX Connection Authorization and support Option 1. The BCU key feature creates a password to protect device configuration, but this password cannot be reset without entering the current password, creating a permanent lockout condition. An attacker with network access to the KNX installation can purge all devices lacking additional security options, then set a BCU key to lock every device. Physical attackers can exploit the same vulnerability if they can access the device directly.

Impact

Successful exploitation grants an attacker the ability to:

  • Lock KNX devices by setting an unknown BCU key password
  • Prevent legitimate users from resetting or reconfiguring locked devices
  • Purge all devices on the KNX network that lack additional security options
  • Disable building automation functions dependent on the compromised KNX installation

The vulnerability carries a CVSS score of 7.5 (HIGH) due to the network attack vector, low attack complexity, and no required privileges or user interaction.

Remediation and Mitigation

No vendor patch is currently available for this vulnerability. Until a firmware update is released, organizations should:

  1. Segment KNX networks from untrusted networks and the public internet
  2. Enable additional security options on all KNX devices that support them
  3. Disable KNX Connection Authorization Option 1 where possible
  4. Implement network monitoring for unauthorized BCU key setting attempts
  5. Restrict physical access to all KNX devices and controllers
  6. Apply the principle of least privilege to KNX network access

For detailed information on building automation security, check our security news section.

Security Insight

This vulnerability highlights a recurring pattern in IoT and building automation ecosystems: authentication mechanisms that lack proper recovery procedures create permanent denial-of-service vectors. The BCU key lockout mirrors similar issues found in smart lock and industrial control systems where password-based protection becomes a barrier to legitimate access once set by an attacker. Organizations should treat KNX devices as critical infrastructure and apply network segmentation as a compensating control until the vendor addresses the authentication reset issue.

Further Reading

Share:

Never miss a critical vulnerability

Get real-time security alerts delivered to your preferred platform.

Related Advisories

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.