---
schema: 1
kind: vulnerability
title: "CVE-2023-4346 — KNX building-automation protocol: account-lockout DoS added to CISA KEV, no software patch (CVSS 7.5)"
headline: "A three-year-old KNX Connection Authorization lockout flaw joins CISA KEV as actively exploited — the fix is procedural, not a patch"
summary: >
  CISA added CVE-2023-4346 to its Known Exploited Vulnerabilities catalog on 2026-07-15, marking
  the KNX Connection Authorization Option-1 account-lockout flaw as known-exploited three years
  after disclosure. An attacker with network (or physical) access to a KNX installation can purge
  unprotected devices and set a BCU key, permanently locking legitimate operators out with no
  reset path; there is no software patch — the fix is procedural. Relevant to any Swiss/European
  critical-infrastructure or public-sector estate running KNX building automation (HVAC, lighting,
  access control, BMS).
discovered_at: "2026-07-16T04:36:00Z"
event_date: "2026-07-15"
run_id: 2026-07-16T0409Z-intel
priority: notable
immediate_action: null
tags: [vulnerabilities, dos, actively-exploited, cisa-kev, ot-ics, no-patch]
regions: [europe]
sectors: [energy, water, healthcare, public-sector, manufacturing]
entities: []
techniques: [T1499]
affected_products: ["KNX Connection Authorization Option 1 devices (no BCU key set)"]
cves:
  - id: CVE-2023-4346
    cvss: "7.5"
    epss: null
    type: dos
    vector: zero-click
    auth: pre-auth
    status: [exploited, cisa-kev, no-patch, mitigation-only]
    affected: "All versions of KNX devices using Connection Authorization Option 1 with no BCU key set"
    fixed: "No software patch — procedural mitigation only (set the BCU key per the KNX Secure Checklist)"
sources:
  - url: "https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01"
    publisher: "CISA (ICS Advisory ICSA-23-236-01)"
    date: "2026-07-15"
    role: primary
  - url: "https://www.cisa.gov/news-events/alerts/2026/07/15/cisa-adds-two-known-exploited-vulnerabilities-catalog"
    publisher: "CISA"
    date: "2026-07-15"
    role: primary
closed_sources: []
evidence:
  - quote: "Exploitable remotely/low attack complexity/known public exploitation"
    publisher: "CISA (ICS Advisory ICSA-23-236-01)"
  - quote: "If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX installation, purge all devices without additional security options enabled, and set a BCU key, locking the device."
    publisher: "CISA (ICS Advisory ICSA-23-236-01)"
verification: single-source-national-cert
sourcing_note: "CISA is the disclosing authority for both the KEV addition and the underlying ICS advisory (ICSA-23-236-01, updated the same day with the known-public-exploitation note); treated as a single-source national-authority disclosure. No independent exploitation telemetry was located. The T1499 (Endpoint Denial of Service) mapping is the closest Enterprise ATT&CK analogue for an availability-only lockout of a control-system device; ATT&CK-for-ICS readers may prefer a Denial-of-Control framing."
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 2
watchlist_hit: false
actions:
  - "Set the BCU key on every KNX Connection Authorization Option-1 device that lacks one (per the KNX Secure Checklist) and place IP-KNX routers/gateways behind a firewall, off any internet-reachable segment — there is no patch, so segmentation and commissioning hygiene are the only controls."
migrated_from: null
---

CISA added **CVE-2023-4346** to its Known Exploited Vulnerabilities catalog on 15 July 2026, alongside the Oracle E-Business Suite flaw, and updated the underlying ICS advisory to carry a *"known public exploitation"* note ([CISA ICSA-23-236-01, 2026-07-15](https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01); [CISA KEV alert, 2026-07-15](https://www.cisa.gov/news-events/alerts/2026/07/15/cisa-adds-two-known-exploited-vulnerabilities-catalog)). The flaw itself is three years old — reported by Felix Eberstaller of Limes Security and published in August 2023 — and had no prior KEV listing until this update. KNX is a widely deployed European building-automation bus protocol (KNX Association is headquartered in Belgium) used for HVAC, lighting, access control and BMS integration, so the exposure sits under any large public-sector or critical-infrastructure estate with smart-building controls.

The design flaw (CWE-645, overly restrictive account-lockout mechanism, CVSS 7.5, availability-only) is in KNX Connection Authorization Option 1: any device that has never had its BCU (Bus Coupling Unit) key set can be purged by an attacker with network access to the KNX installation, who then sets a new BCU key and permanently locks legitimate operators out — with no reset path short of the current password ([CISA ICSA-23-236-01, 2026-07-15](https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01)). An attacker with only physical access to the bus can do the same. KNX Association has issued no software fix in three years; the remediation is entirely procedural — set the BCU key during commissioning.

**Defender takeaway:** the exposure surface is the IP-KNX router/gateway that bridges the building bus onto an IT or internet-reachable network, so treat any such gateway as a priority segmentation target regardless of patch status. This is a configuration and behavioural signal, not a network signature: monitor KNX/ETS project-management logs and BCU-key-set events for unexpected changes, and confirm every finished project handed over to a building owner has its BCU key set. The KEV addition is the exploitation signal used here; the associated federal remediation deadline carries no operational weight for this audience.
