CVE-2023-4346
HIGH(7.5)KEV — Aktiv ausgenutztCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- CVSS 7.5 — Hoch
- Im CISA KEV-Katalog (aktiv ausgenutzt)
Erwähnungen (letzte 60 Tage)
CISA KEV
Bestätigt ausgenutzt
EPSS-Score
1.3%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
7.5
Technische Schwere
SecBoard-Einordnung
CVE-2023-4346 betrifft KNX-Geräte, die KNX Connection Authorization mit Option 1 unterstützen. Die Schwachstelle ermöglicht es einem Angreifer, Geräte zu sperren, indem ein BCU-Schlüssel gesetzt wird, der ohne das aktuelle Passwort nicht zurückgesetzt werden kann. Dies führt zu einem Denial of Service, da Benutzer den Zugriff auf das Gerät verlieren und es nicht zurücksetzen können. Die Schwachstelle wird als hochkritisch eingestuft (CVSS 7.5) und ist im CISA KEV-Katalog gelistet, was bedeutet, dass sie aktiv ausgenutzt wird. Obwohl die EPSS-Wahrscheinlichkeit mit 1% niedrig ist, unterstreicht die aktive Ausnutzung die Dringlichkeit der Bedrohung. Security-Teams sollten umgehend prüfen, ob sie betroffene KNX-Geräte einsetzen. Da keine spezifischen Patches oder Versionen genannt werden, sollten Herstellerempfehlungen zur Absicherung oder Deaktivierung der anfälligen Funktion (Option 1 der KNX Connection Authorization) befolgt werden, um eine Sperrung der Geräte zu verhindern.
KI-gestützte Einordnung auf Basis der NVD-Daten.
Beschreibung
KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX installation, purge all devices without additional security options enabled, and set a BCU key, locking the device. Even if a device is not connected to a network, an attacker with physical access to the device could also exploit this vulnerability in the same way.