boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Monday, October 5, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2023-4346

KNX Association KNX Protocol Connection Authorization Option 1
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0129   69.3   YES
AFFECTED
  Product                                         Versions     Fixed
  KNX Protocol Connection Authorization Option 1  unspecified  —
TIMELINE
  Aug 14  Reserved by icscert
  Aug 29  Published (CNA: icscert)
  Jul 15  Added to CISA KEV, remediation due 2026-07-29
  Jul 30  DUE DATE PASSED — CVE-2023-4346 (KNX Association KNX Protocol Connection Authorization Option 1). CISA remediation deadline was July 29, 2026; still in catalog.
CWE-645 · CNA: icscert · CVSS v3.1 · 2 references · KEV due July 29, 2026

Description

KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX installation, purge all devices without additional security options enabled, and set a BCU key, locking the device. Even if a device is not connected to a network, an attacker with physical access to the device could also exploit this vulnerability in the same way.

Lifecycle

Complete event history — 4 events, chronological
DateEventDetail
August 14, 2023ReservedReserved by icscert
August 29, 2023PublishedPublished (CNA: icscert)
July 15, 2026KEV ADDEDAdded to CISA KEV, remediation due 2026-07-29
July 30, 2026DUE DATE PASSEDDUE DATE PASSED — CVE-2023-4346 (KNX Association KNX Protocol Connection Authorization Option 1). CISA remediation deadline was July 29, 2026; still in catalog.

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
KNX AssociationKNX Protocol Connection Authorization Option 1———

Weaknesses

CWE-645

References (2)

Related

Authoritative record: CVE-2023-4346 at cve.org

Vendors: knx association

Weaknesses: CWE-645

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2023-4346 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Monday, October 5, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.