Overly restrictive account lockout mechanism in KNX firmware - CVE-2023-4346
Published: July 17, 2026
KNX firmware
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an overly restrictive account lockout mechanism in KNX Connection Authorization Option 1 handling when interfacing with the KNX installation to purge devices and set a BCU key. A remote attacker can purge devices without additional security options enabled and set a BCU key to cause a denial of service.
Devices are affected when no BCU key is currently set, and exploitation may leave users unable to regain access to the device or reset it.