CVE-2023-4346

7.5 HIGH CISA KEV - Actively Exploited
Published: August 29, 2023 Modified: July 16, 2026
View on NVD

Description

KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX installation, purge all devices without additional security options enabled, and set a BCU key, locking the device. Even if a device is not connected to a network, an attacker with physical access to the device could also exploit this vulnerability in the same way.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01
Source: ics-cert@hq.dhs.gov
Third Party Advisory US Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-4346
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

3 reference(s) from NVD

Quick Stats

CVSS v3 Score
7.5 / 10.0
EPSS (Exploit Probability)
0.9%
55th percentile
Exploitation Status
Actively Exploited
Remediation due: 2026-07-29

Weaknesses (CWE)

Affected Vendors

knx