16 July 2026
Reference: CVE-2023-4346
1. What is being reported?
The KNX Association has identified a vulnerability in their KNX Protocol Connection Authorization Option 1. This flaw means that if an attacker gains access to the network or physical device, they can set a password that cannot be reset without knowing the current one. This effectively locks out legitimate users from managing their devices.
2. What this means in plain English
For small organisations using KNX smart building technology, this means someone could take control of your building systems and prevent you from accessing or controlling them. This could disrupt heating, lighting, or security systems, causing inconvenience or safety concerns.
3. Could this affect a small business?
If your organisation uses KNX devices with this specific connection authorization option, especially if these devices are connected to a network or physically accessible, you could be at risk. If you do not use KNX technology, or your devices have additional security measures, you are likely not affected.
4. What to do now
- Check with your IT provider or building systems supplier if your KNX devices use Connection Authorization Option 1.
- Ask for and apply any security updates or mitigations recommended by the device vendor.
- Ensure physical access to KNX devices is restricted to trusted personnel only.
- Review your network security to limit who can access the KNX installation.
5. Ask your IT provider
Can you confirm if our KNX devices use Connection Authorization Option 1, and what steps are being taken to protect us from the known lockout vulnerability CVE-2023-4346?
6. Bottom line
If you use KNX smart building devices, act now to prevent attackers from locking you out of your systems.
Information based on CISA KEV, NVD, and reputable security reporting.