PT-2023-28831 · Unknown · Knx Devices
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
KNX Protocol (affected versions not specified)
Description
Devices using KNX Connection Authorization that support Option 1 are susceptible to a lockout mechanism issue. An attacker with network access or physical access to the device can utilize the BCU key feature to set a password, effectively locking the device. Because this password often cannot be reset without the current credentials, users may be permanently unable to regain access. Real-world incidents known as KNXlock attacks have been observed, resulting in the permanent lockout of building automation devices such as lighting, heating, and shutters.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Knx Devices