Independent perspective. Actionable security.Know what matters · Reduce exposure

Vulnerability Assurance / Intelligence

KNX Protocol Connection Authorization Option 1 Lockout Vulnerability

Historical catalog analysis: CISA added this entry on July 15, 2026. The entry reflects catalog information retrieved on August 31, 2026, not a snapshot archived on the inclusion date. Check current vendor guidance before acting.

What the vulnerability is

CVE-2023-4346 describes a vulnerability (CWE-645) within the KNX Protocol Connection Authorization Option 1. The flaw centers on an overly restrictive account lockout mechanism. If additional security options are not enabled, this vulnerability could allow an attacker to purge all devices and set a BCU key to lock the device.

Exposure and applicability

This vulnerability applies specifically to systems utilizing the KNX Protocol Connection Authorization Option 1. The risk is most acute for environments where additional security options have been disabled or were not implemented, as these settings act as a prerequisite for the reported impact (device purging).

Infrastructure owners should prioritize assets that are exposed to the internet, as this increases the potential for remote interaction with the protocol’s authorization mechanism. This vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) catalog on July 15, 2026.

Remediation priorities

Our analysis suggests the following prioritization for vulnerability management teams:

  1. Asset Identification: Identify all devices and controllers utilizing KNX Protocol Connection Authorization Option 1.
  2. Exposure Assessment: Prioritize remediation for assets with direct or indirect internet exposure, as these represent the highest risk of external exploitation.
  3. Vendor Mitigation Application: Apply mitigations according to specific vendor instructions. Because this is a protocol-level issue, the implementation of fixes may vary by hardware manufacturer.
  4. Security Option Review: Evaluate whether “additional security options” are enabled on affected devices to determine if the risk of full device purging is mitigated or remains active.

How to validate remediation

Verification must go beyond a version check or the confirmation that a patch was deployed. To ensure exposure has been reduced, defenders should:

  • Verify Configuration: Confirm through administrative interfaces that the specific vendor-recommended mitigations are active and that additional security options are enabled where supported.
  • Test Access Controls: In a controlled environment, validate that the account lockout mechanism no longer permits unauthorized purging or BCU key modification.
  • Network Validation: Verify that network segmentation or firewall rules have successfully restricted access to the KNX protocol to authorized management workstations only.

Limits and open questions

Applying vendor mitigations could reduce the likelihood of exploitation, but residual risk remains if the underlying network architecture allows unauthorized access to the protocol. It is currently unknown whether this vulnerability has been utilized in ransomware campaigns. Furthermore, because remediation depends on individual vendor instructions, there is no single universal patch for all KNX-compliant devices; consistency across a heterogeneous environment must be manually verified.

Source and editorial note

CVE-2023-4346: KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability · Source date: July 15, 2026 · Retrieved August 31, 2026.

Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.

Archive date: July 18, 2026. The displayed post date is assigned three days after the source date to organize this retrospective archive; it does not mean this site published the analysis then. First published by this site: September 03, 2026 at 02:54 UTC.

Request a Vulnerability Assessment

Turn security intelligence into action.

Discuss your exposure, priorities, and the evidence needed to validate the outcome.

Request a security assessment ↗

Turn security intelligence into action.

Understand exposure, prioritize the response, and define evidence for the outcome.

Request a Security Assessment