CVE-2023-4346

KEV
Published: Ago 29, 2023 Last Modified: Nov 21, 2024 EU-VD ID: EUVD-2023-54211 Aliases: GSD-2023-4346
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,5
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high

Description

AI Translation Available


KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX installation, purge all devices without additional security options enabled, and set a BCU key, locking the device. Even if a device is not connected to a network, an attacker with physical access to the device could also exploit this vulnerability in the same way.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0005
Percentile
0,1th
Updated

EPSS Score Trend (Last 75 Days)

645

Overly Restrictive Account Lockout Mechanism

Incomplete
Common Consequences
Security Scopes Affected:
Availability
Potential Impacts:
Dos: Resource Consumption (Other)
Applicable Platforms
All platforms may be affected
View CWE Details
Application

Connection Authorization by Knx

cpe:2.3:a:knx:connection_authorization:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://www.cisa.gov/news-events/ics-advisories/icsa-23-236…
Third Party Advisory US Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01
https://www.cisa.gov/news-events/ics-advisories/icsa-23-236…
Third Party Advisory US Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01