PT-2023-28831 · Unknown · Knx Devices
Felix Eberstaller
+1
·
Published
2023-08-29
·
Updated
2023-09-11
·
CVE-2023-4346
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
KNX devices (affected versions not specified)
Description
The issue affects KNX devices that use KNX Connection Authorization and support Option 1. Depending on the implementation, these devices are vulnerable to being locked, and users may be unable to reset them to gain access. The BCU key feature can be used to create a password, but this password often cannot be reset without entering the current password. An attacker with network access or physical access to the device could exploit this issue by interfacing with the KNX installation, purging devices without additional security options, and setting a BCU key to lock the device.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Knx Devices