This paper describes two denial of service attacks against the Z-Wave protocol and their effects on smart home gateways. Both utilize modified unencrypted packets, which are used in the inclusion phase and during normal operation. These are the commands Nonce Get/S2 Nonce Get and Find Nodes In Range. This paper shows how both can be manipulated and used to block a Z-Wave gateway's communication processing which in turn disables the whole Z-Wave network connected to it
Cite
@article{arxiv.2001.08497,
title = {Crushing the Wave -- new Z-Wave vulnerabilities exposed},
author = {Noureddine Boucif and Frederik Golchert and Alexander Siemer and Patrick Felke and Frederik Gosewehr},
journal= {arXiv preprint arXiv:2001.08497},
year = {2020}
}