Please include the following specifications in your report:
- Type + Order Number
- Product, including product number / affected devices
- Software version
- Your first and last name
- Name of the organization
- Country
- Email address
- Confirmation of recognition as the finder
- Phone number (optional)
We also need a description of the vulnerability that includes the following information:
- Configuration of the application
- Description of the operating environment
- Detailed description of the vulnerability
- Type of security vulnerability (e.g., “denial-of-service,” SQL injection)
- Information on how the vulnerability can be exploited
- Known impacts of the security vulnerability
- Information on whether, to the best of your knowledge, the vulnerability is already being actively exploited.
Data Protection (GDPR)
We process your personal data (e.g., name and email address) exclusively to handle your report and to fulfill our obligations under the Cyber Resilience Act. Data will only be shared with third parties (such as CERT@VDE) in anonymized form, unless you expressly consent to being named. Detailed information about your rights and our data processing practices can be found in our Datenschutzerklärung.
Cooperation with CERT@VDE and CVE Creation
After we have verified your report internally, we work closely with CERT@VDE. As a recognized coordinating body, CERT@VDE supports us in:
- Registering and assigning an official CVE (Common Vulnerabilities and Exposures) number.
- Quality assurance of the technical report.
- Publishing the joint security advisory on the CERT@VDE platform.
Publication follows the principle of Coordinated Vulnerability Disclosure (CVD) and occurs only once a security update (patch) or an effective workaround is available to our customers.
Data Sharing:
Your data will be treated confidentially. As part of our collaboration with CERT@VDE, we will only share personal data if you expressly consent to it (e.g., to be credited as the discoverer). Otherwise, , all communication with CERT@VDE is conducted in a fully anonymized or pseudonymized manner.
Our Process and Response Times (SLA)
We are committed to transparent and prompt processing:
- Acknowledgment of receipt: You will receive confirmation that your report has been received within 48 hours (2 business days).
- Status Updates: We will keep you regularly informed about the progress of the issue.
- Coordination: We will coordinate the timing of the release (patch) closely with you.
Fair Play (Safe Harbor)
If you act in good faith, do not damage our systems during testing, and treat data confidentially, we will not take any legal action against you.
We will protect your identity and, if you wish, credit you by name as the discoverer when the vulnerability is disclosed.