DIRAS TAKE
Urgent: CISA added this issue to the Known Exploited Vulnerabilities catalog with a 2026-07-29 remediation deadline, so prioritize mitigations immediately for internet-exposed or mission-critical KNX installations.
What is CVE-2023-4346?
Remote or local attackers can lock KNX devices that use the KNX Protocol Connection Authorization Option 1, causing device access to be lost and preventing resets. CVE-2023-4346 affects all versions of the KNX Protocol Connection Authorization Option 1 implementation. An attacker with network access to the KNX installation can purge devices and set a BCU key to lock them; an attacker with physical access can perform the same actions locally.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Which versions of KNX Association KNX Protocol Connection Authorization Option 1 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| KNX Protocol Connection Authorization Option 1 | all versions |
Is CVE-2023-4346 being exploited?
CISA added CVE-2023-4346 to the Known Exploited Vulnerabilities catalog on 2026-07-15, and U.S. federal agencies were required to fix or mitigate it by 2026-07-29.
How to fix CVE-2023-4346
- Follow vendor guidance and apply any recommended mitigations for KNX Connection Authorization Option 1.
- Restrict network exposure of KNX installations; block or segment access from untrusted networks.
- Disable or replace Connection Authorization Option 1 where feasible until a vendor fix is available.
- Improve physical security for devices and monitor device logs and network traffic for unauthorized purge or BCU key actions.
Frequently asked questions
Is CVE-2023-4346 being actively exploited?
CISA added CVE-2023-4346 to the Known Exploited Vulnerabilities catalog on 2026-07-15, and federal agencies were required to remediate by 2026-07-29.
Which KNX Protocol Connection Authorization Option 1 versions are affected by CVE-2023-4346?
All versions of the KNX Protocol Connection Authorization Option 1 implementation are listed as affected.
Is there a patch for CVE-2023-4346?
There is no fixed version listed; follow the KNX Association's guidance and apply recommended mitigations until a vendor patch is published.
What can an attacker do with CVE-2023-4346?
An attacker can purge devices without additional security options enabled and set a BCU key to lock devices, denying legitimate access to the KNX installation.
References
- nvd.nist.gov/vuln/detail/CVE-2023-4346
- cve.org/CVERecord?id=CVE-2023-4346
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-4346
- cisa.gov/news-events/ics-advisories/icsa-23-236-01
- All KNX Association CVEs on CVE Radar
- CVEs published in September 2026