CISA Adds KNX Protocol Connection Authorization Option 1 (CVE‑2023‑4346) and Oracle E‑Business Suite (CVE‑2026‑46817) to KEV Catalog
What It Is – The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has placed two actively‑exploited flaws into its Known Exploited Vulnerabilities (KEV) catalog: an overly‑restrictive account‑lockout issue in KNX building‑automation devices (CVE‑2023‑4346, CVSS 7.5) and an unauthenticated privilege‑escalation bug in Oracle E‑Business Suite Payments (CVE‑2026‑46817).
Exploitability – Both vulnerabilities are confirmed to be exploited in the wild. The KNX flaw allows an attacker with network or physical access to lock a device by setting a BCU key, denying legitimate users. The Oracle bug enables remote takeover over HTTP without authentication; Defused Cyber reported active exploitation shortly after the vendor’s patch.
Affected Products –
- KNX Association – KNX devices using Connection Authorization Option 1.
- Oracle – Oracle E‑Business Suite Payments versions 12.2.3 through 12.2.15.
Why It Matters for Compliance & Audit Readiness –
- SOC 2 Access Controls – Both flaws bypass logical‑access safeguards (account lockout, privilege management) that map directly to CC6.1 (Logical Access Control) and CC6.2 (System Operations).
- Continuous Evidence – Demonstrating timely patching and configuration validation is essential audit evidence for “risk mitigation” criteria.
- Enterprise Buyer Expectations – Federal and large‑enterprise customers now require proof that vendors actively remediate KEV‑listed flaws; a missing control can stall contracts.
Recommended Actions –
- Patch Immediately – Apply Oracle’s Critical Patch Update and any KNX firmware releases that address CVE‑2023‑4346.
- Validate Lockout Settings – Verify that KNX devices enforce proper lockout thresholds and that BCU keys are rotated securely.
- Map to SOC 2 Controls – Document the remediation in your SOC 2 access‑control evidence set (CC6.1, CC6.2).
- Enable Continuous Monitoring – Use automated vulnerability scanners to flag any re‑appearance of these CVEs and retain scan logs as audit artifacts.
Source: Security Affairs