Dismissed
Permalink
CVE-2026-3588
7.5 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Adjacent (A)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): High (H)
- User Interaction (UI): None (N)
- Scope (S): Changed (C)
- Confidentiality (C): High (H)
- Integrity (I): Low (L)
- Availability (A): Low (L)
- Modified Attack Vector (MAV): Adjacent (A)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): High (H)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Changed (C)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): Low (L)
by @mweinelt Activity log
- Created suggestion
-
@mweinelt
ignored
4 packages
- python312Packages.dirigera
- python313Packages.dirigera
- python314Packages.dirigera
- home-assistant-custom-components.dirigera_platform
- @mweinelt dismissed
Server-Side Request Forgery (SSRF) in ikea dirigera
A server-side request forgery (SSRF) vulnerability in IKEA Dirigera v2.866.4 allows an attacker to exfiltrate private keys by sending a crafted request.
References
-
https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-3588 third-party-advisory
Affected products
dirigera
- =<2.866.4
Ignored packages (4)
pkgs.python312Packages.dirigera
Module for controlling the IKEA Dirigera Smart Home Hub
pkgs.python313Packages.dirigera
Module for controlling the IKEA Dirigera Smart Home Hub
pkgs.python314Packages.dirigera
Module for controlling the IKEA Dirigera Smart Home Hub