CVE-2022-39065
Published on: Not Yet Published
Last Modified on: 10/18/2022 02:08:00 PM UTC
Certain versions of Tradfri Gateway E1526 from Ikea contain the following vulnerability:
A single malformed IEEE 802.15.4 (Zigbee) frame makes the TRÅDFRI gateway unresponsive, such that connected lighting cannot be controlled with the IKEA Home Smart app and TRÅDFRI remote control. The malformed Zigbee frame is an unauthenticated broadcast message, which means all vulnerable devices within radio range are affected. CVSS 3.1 Base Score: 6.5 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- CVE-2022-39065 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
Ikea - TRÅDFRI gateway system version < 1.19.26
CVSS3 Score: 6.5 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
ADJACENT_NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | NONE | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
CyRC Vulnerability Advisory: CVE-2022-39065 IKEA TRÅDFRI smart lighting gateway | Synopsys | www.synopsys.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Ikea | Tradfri Gateway E1526 | - | All | All | All |
Operating System | Ikea | Tradfri Gateway E1526 Firmware | All | All | All | All |
- cpe:2.3:h:ikea:tradfri_gateway_e1526:-:*:*:*:*:*:*:*:
- cpe:2.3:o:ikea:tradfri_gateway_e1526_firmware:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CyRC Vulnerability Advisory: CVE-2022-39065 IKEA TRÅDFRI smart lighting gateway ift.tt/p1jUnRA ift.tt/1oMuUQf | 2022-10-05 13:19:13 |
![]() |
"an attacker could advantage of two vulnerabilities (tracked under CVE-2022-39064 and CVE-2022-39065) in the Ikea T… twitter.com/i/web/status/1… | 2022-10-06 04:23:28 |
![]() |
CyRC Vulnerability Advisory: CVE-2022-39065 IKEA TRÅDFRI smart lighting gateway bit.ly/3STB508 | 2022-10-06 12:00:05 |
![]() |
CyRC Vulnerability Advisory: CVE-2022-39065 IKEA TRÅDFRI smart lighting gateway bit.ly/3rBiJFf | 2022-10-06 14:23:39 |
![]() |
CyRC Vulnerability Advisory: CVE-2022-39065 IKEA TRÅDFRI smart lighting gateway | Synopsys synopsys.com/blogs/software… | 2022-10-08 23:58:41 |
![]() |
Potentially Critical CVE Detected! CVE-2022-39065 A single malformed IEEE 802.15.4 (Zigbee) frame makes the TRÅDFRI… twitter.com/i/web/status/1… | 2022-10-14 16:55:59 |
![]() |
CVE-2022-39065 | 2022-10-14 16:39:01 |