Vulnerability report
The security of our products and systems is important to us.
Coordinated Vulnerability Disclosure (CVD)
This responsible disclosure policy is designed to identify and promptly address new vulnerabilities and security issues in the hardware, software, or services provided by Schmidiger GmbH. It is based on the EU Cyber Resilience Act (CRA).
Scope
Security vulnerabilities in all products and services provided by Schmidiger GmbH can be reported through this reporting channel.
Reporting a Vulnerability
If you have discovered a potential security vulnerability in a Schmidiger product or service, we ask that you report it responsibly. Please use the form below to do so. Please include as much information as possible in your message, in German or English:
- Affected product or system
- Software/firmware version
- Detailed description of the vulnerability (with evidence, if possible)
- Steps to reproduce the vulnerability
- Impact of the vulnerability (if known)
- Your contact information and how to reach you
Our Process
- We will confirm receipt of the report promptly.
- We will review and assess the reported vulnerability.
- If necessary, we will contact you with questions or to request additional information.
- Depending on the nature and severity of the vulnerability, we take appropriate measures to address it and, if necessary, notify affected customers and/or the relevant authorities.
Responsible Disclosure
We ask that you:
- refrain from unauthorized access to data,
- do not modify or delete any data,
- do not intentionally disrupt any systems,
- not to disclose information about the vulnerability publicly before a solution is available.
Provided that you act in good faith, Schmidiger GmbH will not take legal action against security researchers who comply with this policy.