PT-2023-28831 · Unknown · Knx Devices

·

CVE-2023-4346

·

Published

2023-08-29

·

Updated

2026-07-17

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions KNX Protocol (affected versions not specified)
Description Devices using KNX Connection Authorization that support Option 1 are susceptible to a lockout mechanism issue. An attacker with network access or physical access to the device can utilize the BCU key feature to set a password, effectively locking the device. Because this password often cannot be reset without the current credentials, users may be permanently unable to regain access. Real-world incidents known as KNXlock attacks have been observed, resulting in the permanent lockout of building automation devices such as lighting, heating, and shutters.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-4346

Affected Products

Knx Devices