CISA Adds KNX Protocol Connection Authorization Flaw to KEV Catalog
A critical account lockout vulnerability in the KNX Protocol Connection Authorization Option 1 is currently being exploited in the wild.
CISA has added CVE-2023-4346, a vulnerability in the KNX Association KNX Protocol Connection Authorization Option 1, to its Known Exploited Vulnerabilities catalog. The flaw, identified as an overly restrictive account lockout mechanism (CWE-645), could allow an attacker to purge all devices lacking additional security options and lock them by setting a BCU key.
The vulnerability is confirmed to be under active exploitation. Federal agencies are required to apply vendor-provided mitigations by July 29, 2026, in accordance with BOD 26-04. Stakeholders are advised to evaluate their internet-exposed assets and ensure compliance with CISA's forensic triage and patching guidelines.
Sources
- CISA KEV Original source
Continue Reading
FulcrumSec Claims Manchester Airport Breach, 86 GB Stolen
Extortion group FulcrumSec says it stole 86 GB from Manchester Airports Group, exposing detailed travel data.
Anthropic tackles Claude session hijacking via infostealers
Anthropic warns that infostealer malware is stealing Claude login sessions to drain accounts.
AI agents can be tricked into installing malware via unclaimed code packages
Researchers found 120 unregistered domains in AI documentation that could be hijacked to infect corporate networks.