Independent industrial cybersecurity.Know what matters · Reduce exposure

SCADA Cyber / Intelligence

KNX Protocol Connection Authorization Option 1 Lockout Vulnerability

Historical catalog analysis: CISA added this entry on July 15, 2026. The entry reflects catalog information retrieved on August 31, 2026, not a snapshot archived on the inclusion date. Check current vendor guidance before acting.

What the vulnerability is

CVE-2023-4346 describes an overly restrictive account lockout mechanism (CWE-645) within the KNX Protocol Connection Authorization Option 1. This flaw could be leveraged by an attacker to purge all devices on a network, provided that additional security options are not enabled. Furthermore, the vulnerability allows for the setting of a BCU key, which can result in the device being locked.

Exposure and applicability

This vulnerability specifically applies to environments utilizing the KNX Protocol Connection Authorization Option 1. Because KNX is widely used for building automation and control systems, this affects facility managers and OT security leaders overseeing integrated industrial or commercial building operations.

On July 15, 2026, CISA added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. While a remediation deadline of July 29, 2026, was established for covered federal agencies, private sector asset owners should evaluate their exposure based on their specific operational risk profile.

Remediation priorities

Our analysis suggests the following prioritized actions for OT operators and integrators:

  1. Configuration Audit: Identify all building automation segments utilizing KNX Protocol Connection Authorization Option 1. This is a prerequisite for determining if the environment is susceptible to the lockout mechanism.
  2. Security Option Review: Evaluate whether “additional security options” are enabled. According to the reported vulnerability, the ability to purge devices is contingent on these additional options being absent.
  3. Vendor Mitigation Deployment: Apply mitigations as specified by the KNX Association. This should be coordinated through a formal change control process to avoid accidental triggers of the lockout mechanism during updates.
  4. Network Segmentation: Ensure that building automation networks are isolated from general IT networks and the public internet to reduce the likelihood of an external attacker reaching the protocol authorization interface.

How to validate remediation

Validation should be performed in accordance with OEM guidance to avoid operational disruption. We recommend the following approach:

  • Configuration Verification: Confirm through system logs or configuration exports that the recommended vendor mitigations have been applied and that additional security options are active where supported.
  • Access Control Audit: Verify that access to the KNX network is restricted to authorized engineering workstations, reducing the attack surface for the lockout mechanism.

Avoid performing active stress tests or simulated lockout attacks on production control equipment without explicit OEM authorization and a verified rollback plan.

Limits and open questions

It remains unknown whether this vulnerability has been utilized in ransomware campaigns. Additionally, while CISA has flagged this as known to be exploited, the specific entry paths used by attackers in real-world scenarios are not detailed in the provided source. Operators should note that applying a mitigation may reduce risk but does not guarantee total prevention of all denial-of-service vectors within building automation protocols.

Source and editorial note

CVE-2023-4346: KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability · Source date: July 15, 2026 · Retrieved August 31, 2026.

Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.

Archive date: July 18, 2026. The displayed post date is assigned three days after the source date to organize this retrospective archive; it does not mean this site published the analysis then. First published by this site: September 02, 2026 at 02:33 UTC.

Request an OT security assessment

Protect the systems your operations depend on.

Discuss your industrial environment, prioritize exposure, and establish evidence that safeguards work.

Request an OT assessment ↗

Protect what operations depend on.

Discuss your risks, priorities, and next steps for stronger safeguards.

Request an OT assessment