---
id: CVE-2023-4346
title: >-

  KNX devices that use KNX Connection Authorization and support Option 1 are,
  depending on the implementation, vulnerable to being locked and users being
  unable to reset them to gain access to the device
summary: >-

  KNX devices that use KNX Connection Authorization and support Option 1 are,
  depending on the implementation, vulnerable to being locked and users being
  unable to reset them to gain access to the device. The BCU key feature on the
  device…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-645
vendor: knx
product: connection_authorization
affected:
  - connection_authorization
published: '2023-08-29'
updated: '2026-07-15'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-4346'
references:
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01'
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-4346
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
epss: 0.01294
epssPercentile: 0.69075
kev: true
kevDateAdded: '2026-07-15'
kevDueDate: '2026-07-29'
kevRansomware: false
exploited: true
ingestedAt: '2026-07-15T18:45:15.884Z'
---

## Overview


KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX installation, purge all devices without additional security options enabled, and set a BCU key, locking the device. Even if a device is not connected to a network, an attacker with physical access to the device could also exploit this vulnerability in the same way. 



## Affected

- `connection_authorization`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
