KNX develops a specialized suite of building-automation and smart-building engineering tools and middleware, including its widely used ETS platform and connection-authorization components that configure and manage networked devices across installations. The recurrent vulnerabilities cluster around credential-handling practices and memory-safety issues in the engineering tooling, reflecting the embedded and legacy character of industrial control software; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Knx over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-4346HIGH
KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gai | Aug 29, 2023 | 7.5 | 67 | YES | NO |
CVE-2015-8299CRITICAL Buffer overflow in the Group messages monitor (Falcon) in KNX ETS 4.1.5 (Build 3246) allows remote attackers to execute arbitrary code via a crafted KNXnet/IP UDP packet. | Aug 29, 2017 | 9.8 | 32 | NO | NO |
CVE-2021-36799HIGH KNX ETS5 through 5.7.6 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local users to read project information. NOTE: This vulnerability onl | Jul 19, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-43575MEDIUM KNX ETS6 through 6.0.0 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local users to read project information, a similar issue to CVE-2021- | Nov 9, 2021 | 5.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Knx.
Media articles that mention a CVE ID that affects a product developed by Knx — matched by CVE ID, not by vendor name.