knx CVE Vulnerabilities & CVE List (4)

Products (CPE): — CVEs: 4

knx vulnerability overview

Aggregates CVE and security vulnerability intelligence across all knx-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk buffer overflow and related problems; some flaws may lead to vendor impact application crash, affecting vendor surface software deployment and vendor surface production workloads scenarios.

Vulnerability distribution trend (last 24 months)

Showing 14 of 4 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2023-4346 KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX instal [email protected] 7.5 0.48% 2023-08-29 2024-11-21
CVE-2021-43575 KNX ETS6 through 6.0.0 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local users to read project information, a similar issue to CVE-2021-36799. NOTE: The vendor disputes this because it is not the responsibility of the ETS to securely store cryptographic key material when it is not being exported [email protected] 5.5 0.31% 2021-11-09 2024-11-21
CVE-2021-36799 KNX ETS5 through 5.7.6 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local users to read project information. NOTE: This vulnerability only affects products that are no longer supported by the maintainer [email protected] 8.8 0.42% 2021-07-19 2024-11-21
CVE-2015-8299 Buffer overflow in the Group messages monitor (Falcon) in KNX ETS 4.1.5 (Build 3246) allows remote attackers to execute arbitrary code via a crafted KNXnet/IP UDP packet. [email protected] 9.8 6.17% 2017-08-29 2026-05-13
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence