Please do not open a public issue for security problems.
Use GitHub's private vulnerability reporting instead: Report a vulnerability (or the Security tab → Report a vulnerability). Only the maintainer sees the report.
Please include, when you can:
- the integration version and the Home Assistant version;
- the intercom model and whether you use local UDP or the Vimar cloud (TLS);
- what an attacker can do and from where (LAN, internet, an authenticated HA user…);
- steps to reproduce, or a proof of concept.
Never paste secrets in the report: SIP password, ha1, the QR payload, cloud tokens or real
SIP IDs. Replace them with placeholders (for example SIP id 12345).
This is a hobby project maintained in spare time, so there are no guaranteed deadlines. The aim is to:
- acknowledge the report within a few days;
- agree on the severity and on a fix, and keep you updated in the private advisory;
- release the fix and then publish the advisory, crediting you unless you prefer otherwise.
Only the latest release receives security fixes. Please update through HACS before reporting.
In scope: the code in this repository (custom_components/vimar_intercom, the Lovelace card and
the tools), for example the HTTP endpoints and WebSocket it exposes, handling of SIP messages
and media, and how credentials are stored and logged. The current safeguards are listed in the
Security section of the README.
Out of scope: vulnerabilities in the Vimar/Elvox devices, their firmware, the Vimar cloud or the official apps (report those to Vimar), and in Home Assistant itself (see Home Assistant's security page).