high Known exploitedREV. 01

CVE-2023-4346KNX Connection Authorization — device lockout with no reset path

Building-automation devices using the KNX protocol (KNX) with Connection Authorization Option 1 can be locked by anyone who reaches the bus: an attacker sets the device key and, without the old key, owners often cannot reset the device.

YOUR NEXT MOVE

Separate the KNX installation from untrusted networks, restrict physical access to devices, and turn on the additional device security options; follow CISA ICSA-23-236-01.

Read the risk

THE VITAL STATS
CVSS score
7.5/ 10
CVSS v3.1
EPSS probability
1%
Likelihood of exploitation
Attack complexity
Low
Conditions needed to exploit
Known exploited
Yes — CISA KEV
CVE published
2023-08-29
Added to KEV
2026-07-15
Exploit published
Not recorded
Confidence
high
Kill chain
impact
MITRE ATT&CK
—
Severity
high

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attacker needsAccess to the network the KNX installation sits on, or physical access to a device.

Behind the card

3 REFERENCES
Field-level provenanceTRACE THE SOURCES +

Which source supports each field, when it was retrieved, and who extracted it.

FieldsSourceRetrievedExtractorConfidence
cvss, exploitation.attack_complexity, exploitation.exploit_available, references, published_atnvd.nist.gov2026-09-23scrty-crds-pipeline/0.1high
exploitation.known_exploited, exploitation.kev_addedcisa.gov2026-09-23scrty-crds-pipeline/0.1high
epssapi.first.org2026-09-23scrty-crds-pipeline/0.1high
title, summary, severity, remediation, mitre_attack, kill_chain, recommended_action, confidence, tags, exploitation.prerequisitesnvd.nist.gov2026-09-23claude-codehigh

Printing history

THE RECORD
  1. r1Initial base card

First printing. This card has not been reprinted since publication.

crds:cve-2023-4346 · CRDS 0.1 · Issued 2026-09-23