Report a Vulnerability

Report a Vulnerability / Vulnerability Disclosure

We welcome responsible reports of potential security vulnerabilities in our products with digital elements. Please report vulnerabilities confidentially using the contact form provided below so that we can review and handle them in a coordinated manner. This reporting channel applies to vulnerabilities in products, software, firmware and relevant hardware components for which Eisenbeiss GmbH is responsible.

This reporting channel is specifically intended to receive vulnerability reports in accordance with applicable regulatory requirements, including the Cyber Resilience Act (Regulation (EU) 2024/2847).

Contact

Please use our contact form to report vulnerabilities. This reporting channel is available at all times and serves as the central point of contact for security-related reports.

Please provide the following information

To enable us to review your report efficiently, please include the following information:

  • affected product,
  • affected version or configuration,
  • description of the vulnerability,
  • date and time of discovery of the vulnerability,
  • clear steps to reproduce the vulnerability,
  • potential impact or risk assessment,
  • technical evidence, such as screenshots, logs or proof of concept,
  • your contact information for follow-up questions.

Incomplete reports can be processed but may result in follow-up questions or delays.

Our Commitments

  • We will treat your report confidentially.
  • We will acknowledge receipt of your report within 5 business days.
  • We will provide you with an initial qualified response within 10 business days, provided that the report contains sufficient information for review.
  • We will strive to address the reported vulnerability in a coordinated and appropriate manner.
  • Non-public information regarding the reported vulnerability will only be made accessible to authorized persons.
  • We prioritize and adress reported vulnerabilities on a risk-based basis and in accordance with our internal vulnerability management processes.

Secure Communication

Secure communication channels should be used when transmitting sensitive information.

  • This page and the contact form are accessible exclusively via a secure connection.
  • Non-public vulnerability information must be treated confidentially

Expectations for Reporters

We ask that you act responsibly and in good faith when investigating and reporting vulnerabilities. In particular we expect you to:

  • not modify, delete, exfiltrate or publish data without authorization,
  • not cause damage or operational disruptions,
  • only perform tests that are necessary to identify and document the vulnerability,
  • not use social engineering techniques,
  • not perform any physical manipulations outside a permissible and legitimate framework,
  • not publish information about the vulnerability before consulting with us,
  • comply with all applicable legal requirements.

Coordinated Disclosure

Please refrain from public disclosure until we have had the opportunity to review the reported vulnerability and take appropriate action. The timing and scope of any disclosure will be coordinated considering the risk, impact and available mitigation measures. Confirmed vulnerabilities may be disclosed through security advisories, release notes, customer information or other appropriate formats.

Legal Notice

If you act in good faith and in accordance with these rules, we generally consider your report to be a contribution to improving product security. Provided that you act in good faith and in accordance with this policy, we do not intend to take legal action, unless there are intentional or grossly negligent violations.

security.txt

You can also find information about our security contact and this reporting channel in our security.txt file. The information contained there is consistent with this page and is updated regularly.