Mesutronic
Coordinated vulnerability disclosure policy (CVD)
Purpose
Mesutronic GmbH places great importance on the security of its products, services and information systems.
This Coordinated Vulnerability Disclosure Policy describes the process for reporting, analysing, handling and disclosing security vulnerabilities. Its purpose is to minimise security risks for customers and users and to enable coordinated cooperation with security researchers and other reporters.
Scope
This policy applies to:
- Products of Mesutronic GmbH
- Software and firmware components
- Web applications operated by Mesutronic
- Digital services and systems under Mesutronic’s responsibility
The following are excluded from this policy:
- Customer-owned systems and networks
- Third-party systems and services
- Social engineering attacks
- Physical attacks on devices or infrastructure
- Denial-of-Service (DoS) and Distributed Denial-of-Service (DDoS) attacks
Reporting Vulnerabilities
Security vulnerabilities can be reported to the Mesutronic PSIRT:
Email: psirt@mesutronic.de
Where possible, please provide the following information:
- Affected product
- Product version
- Software or firmware version
- Description of the vulnerability
- Steps to reproduce the vulnerability
- Potential impact
- Available technical evidence
- Contact details for any follow-up questions
Expectations for Reporters
Mesutronic supports responsible security research. We ask reporters to:
- Not access, modify or delete data without authorisation
- Not disrupt or manipulate systems
- Not use malware
- Not publicly disclose the vulnerability prior to coordinated disclosure
- Comply with all applicable laws and regulations
- Limit investigations to the minimum extent necessary
Handling of Reports
Upon receipt of a report, the following steps are taken:
- Registration of the report
- Technical analysis and validation
- Risk assessment
- Definition of appropriate countermeasures
- Implementation of corrective measures
- Communication with affected parties
Mesutronic aims to meet the following target response times:
- Acknowledgement of receipt within 5 business days
- Initial assessment within 10 business days
The complexity and criticality of a report may affect the time required for processing.
Coordinated Disclosure
Mesutronic follows the principle of Coordinated Vulnerability Disclosure (CVD).
Information about confirmed vulnerabilities will generally only be published once:
- The analysis has been completed
- Appropriate measures are available, or
- Affected users can be adequately informed
The timing and scope of any disclosure will be determined taking into account the risks to customers and users.
Security Advisories
In the event of confirmed vulnerabilities, Mesutronic may publish Security Advisories.
An advisory may contain the following information:
- Description of the vulnerability
- Affected products and versions
- Risk assessment
- Recommended measures
- Available updates or workarounds
- Other relevant technical information
Confidentiality and Data Protection
Information collected for the purpose of processing a vulnerability report will be treated confidentially.
Personal data will only be processed to the extent necessary and in accordance with applicable data protection regulations.
Disclaimer
Submitting a vulnerability report does not create any entitlement to:
- Compensation
- Recognition
- Publication
- Specific response or processing times
Mesutronic reserves the right to assess reports at its own discretion and to decide on further measures. This policy does not create any contractual rights or obligations.