KNX devices locked via BCU key exploit (CVE-2023-4346)
CVE-2023-4346
Actively exploited - CVE-2023-4346 allows attackers on the network to lock KNX devices by setting a BCU key password. CISA KEV confirmed. Apply mitigations immediately.
Actively exploited in the wild - CVE-2023-4346 is a high-severity vulnerability in KNX devices using Connection Authorization Option 1 that lets network attackers lock devices by setting a BCU key password, preventing legitimate access. CISA has confirmed active exploitation; no vendor patch is available yet.
Overview
CVE-2023-4346 affects KNX devices that implement KNX Connection Authorization and support Option 1. The BCU key feature creates a password to protect device configuration, but this password cannot be reset without entering the current password, creating a permanent lockout condition. An attacker with network access to the KNX installation can purge all devices lacking additional security options, then set a BCU key to lock every device. Physical attackers can exploit the same vulnerability if they can access the device directly.
Impact
Successful exploitation grants an attacker the ability to:
- Lock KNX devices by setting an unknown BCU key password
- Prevent legitimate users from resetting or reconfiguring locked devices
- Purge all devices on the KNX network that lack additional security options
- Disable building automation functions dependent on the compromised KNX installation
The vulnerability carries a CVSS score of 7.5 (HIGH) due to the network attack vector, low attack complexity, and no required privileges or user interaction.
Remediation and Mitigation
No vendor patch is currently available for this vulnerability. Until a firmware update is released, organizations should:
- Segment KNX networks from untrusted networks and the public internet
- Enable additional security options on all KNX devices that support them
- Disable KNX Connection Authorization Option 1 where possible
- Implement network monitoring for unauthorized BCU key setting attempts
- Restrict physical access to all KNX devices and controllers
- Apply the principle of least privilege to KNX network access
For detailed information on building automation security, check our security news section.
Security Insight
This vulnerability highlights a recurring pattern in IoT and building automation ecosystems: authentication mechanisms that lack proper recovery procedures create permanent denial-of-service vectors. The BCU key lockout mirrors similar issues found in smart lock and industrial control systems where password-based protection becomes a barrier to legitimate access once set by an attacker. Organizations should treat KNX devices as critical infrastructure and apply network segmentation as a compensating control until the vendor addresses the authentication reset issue.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Related Advisories
An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would ove...
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could pot...
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally....
Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import feature that allows administrator-level attackers to upload arbitrary PHP files by sub...