PT-2023-28831 · Unknown · Knx Devices

Felix Eberstaller

+1

·

Published

2023-08-29

·

Updated

2023-09-11

·

CVE-2023-4346

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions KNX devices (affected versions not specified)
Description The issue affects KNX devices that use KNX Connection Authorization and support Option 1. Depending on the implementation, these devices are vulnerable to being locked, and users may be unable to reset them to gain access. The BCU key feature can be used to create a password, but this password often cannot be reset without entering the current password. An attacker with network access or physical access to the device could exploit this issue by interfacing with the KNX installation, purging devices without additional security options, and setting a BCU key to lock the device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2023-4346

Affected Products

Knx Devices