← Blog · · df00tech

CISA KEV Alert: CVE-2023-4346 – Overly Restrictive Account Lockout in KNX Connection Authorization Enables Brute-Force of Building Automation Systems

vuln-intel KNX Association CVE-2023-4346

What the vulnerability is

CVE-2023-4346 is an overly restrictive account lockout flaw (CWE-645) in KNX Protocol Connection Authorization Option 1. The mechanism intended to lock out repeated failed authorization attempts against a KNX secure connection does not effectively do so, allowing an attacker to brute-force the connection authorization key/password that gates access to a KNX interface or gateway. Successful exploitation grants unauthorized access to KNX building automation devices, including HVAC, lighting, physical access control, and alarm systems.

Affected software

  • Vendor: KNX Association
  • Product: KNX Protocol Connection Authorization Option 1

No specific affected version range or patch date has been published for this entry at this time.

Exploitation status

This CVE is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and is subject to BOD 26-04 prioritized remediation timelines. Its presence in KEV confirms active exploitation in the wild, meaning defenders operating KNX-based building automation environments should treat this as an immediate, actionable risk rather than a theoretical weakness — brute-force attempts against exposed KNXnet/IP gateways should be assumed possible today.

How our detection catches it

Our rule identifies repeated failed KNX/IP secure authorization attempts originating from a single source against a KNX interface or gateway, as well as connection request patterns that bypass expected lockout thresholds. Detection logic correlates authorization failure counts and connection request frequency over a time window from network telemetry, firewall/IDS logs, and KNXnet/IP gateway logs to surface brute-force behavior that the broken lockout mechanism fails to stop on its own. Coverage is shipped for Microsoft Sentinel (KQL), Splunk (SPL), Elastic (EQL), IBM QRadar (AQL), Sumo Logic, Google Chronicle (YARA-L), and CrowdStrike (CQL), so teams can deploy the detection regardless of their SIEM stack.

Get the full detection

For the complete detection logic, tuning guidance, and ready-to-deploy queries across all supported platforms, see the full detection page for CVE-2023-4346.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.