VYPR
Unrated severityNVD Advisory· Published Jun 20, 2023· Updated Dec 9, 2024

CVE-2023-34596

CVE-2023-34596

Description

A vulnerability in Aeotec WallMote Switch firmware v2.3 allows attackers to cause a Denial of Service (DoS) via a crafted Z-Wave message.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Aeotec WallMote Switch firmware v2.3 is vulnerable to a Denial of Service (DoS) via a crafted Z-Wave message, causing the device to become unresponsive.

Vulnerability

The vulnerability exists in Aeotec WallMote Switch firmware version 2.3. It allows an attacker to cause a Denial of Service (DoS) by sending a specially crafted Z-Wave message to the device. The vulnerability appears to be triggered by malformed or unexpected Z-Wave frames that the firmware cannot handle correctly, leading to a crash or hang. The affected product is the Aeotec WallMote Switch (also known as WallMote Quad) running firmware v2.3 [1].

Exploitation

An attacker must be within Z-Wave radio range of the target device (typically up to 30 meters indoors) and able to transmit Z-Wave messages. No authentication is required since Z-Wave devices generally accept commands from any controller within range. The attacker sends a crafted Z-Wave message that exploits the vulnerability; the exact sequence of bytes is described in the vulnerability report [1]. No user interaction is needed.

Impact

Successful exploitation results in the WallMote Switch becoming unresponsive—it stops processing legitimate Z-Wave commands and may require a power cycle to recover. This constitutes a Denial of Service (DoS) condition. There is no indication of data leakage or code execution; the impact is purely on availability of the device.

Mitigation

As of the publication date (2023-06-20), no firmware update has been released to address this vulnerability. The vendor, Aeotec, has not publicly acknowledged the issue or issued a patch [2]. Users are advised to restrict physical access to the device and monitor for any future firmware updates. The CVE is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog as of this writing.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.