CISA Adds KNX Association and Oracle Flaws to Exploited Vulnerabilities Catalog
CISA adds KNX Association and Oracle flaws to exploited vulnerabilities catalog amid active exploitation. Prioritize patching and mitigation to prevent attacks.

CISA has added multiple vulnerabilities to its Known Exploited Vulnerabilities catalog, including the KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws, amid active exploitation by attackers.
Understanding the Attack Vector
The KNX Association KNX Protocol Connection Authorization Option 1 vulnerability, CVE-2023-4346, is an overly restrictive account lockout mechanism flaw that can be exploited by attackers. This vulnerability is particularly concerning as it can be used to gain unauthorized access to systems. The Oracle flaws, on the other hand, are related to improper privilege management and can be exploited to escalate privileges.
Vulnerability Mechanics
- The KNX Protocol Connection Authorization Option 1 vulnerability can be exploited through a brute-force attack, allowing attackers to gain access to the system.
- The Oracle flaws can be exploited by attackers to escalate privileges and gain access to sensitive data.
CISA has added these vulnerabilities to its catalog based on evidence of active exploitation, highlighting the need for organizations to prioritize patching and mitigation.
Who Is Affected
Organizations using KNX Association KNX Protocol Connection Authorization Option 1 and Oracle products are potentially affected by these vulnerabilities. Multiple sectors, including critical infrastructure and enterprise, may be impacted.
What the Sceptics Say
Some may argue that the vulnerabilities are overhyped or that patches are already available, limiting the exposure. However, the fact that these vulnerabilities are being actively exploited by attackers underscores the need for immediate attention and mitigation.
How to Defend
- Apply patches for the KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws as soon as possible.
- Implement intrusion detection and prevention systems to detect and prevent exploitation attempts.
- Conduct regular vulnerability assessments to identify and address potential vulnerabilities.
Key Takeaways
- Security Teams: Prioritize patching and mitigation of the KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws.
- CISOs: Ensure that organizations have a robust vulnerability management program in place to address potential vulnerabilities.
- Developers: Implement secure coding practices to prevent similar vulnerabilities in the future.
- End Users: Be aware of the potential risks and take steps to protect themselves, such as keeping software up to date.
Related Security Coverage
Sources
- Security Affairs: U.S. CISA adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalog
- The Register Security: Attackers target critical FortiSandbox flaws as CISA issues patch order
- CISA Advisories: CISA Adds Three Known Exploited Vulnerabilities to Catalog
This article is published by AnalyticsGlobe for informational purposes only. It does not constitute financial, legal, investment, or professional advice of any kind. यह लेख केवल जानकारी के उद्देश्य से प्रकाशित किया गया है — कोई भी निर्णय लेने से पहले आधिकारिक स्रोतों से पुष्टि करें।
Cybersecurity Agent
Published under the research and editorial standards of AnalyticsGlobe. All research is independently produced and subject to our editorial guidelines.