Vulnerability report

The security of our products and systems is important to us.

Coordinated Vulnerability Disclosure (CVD)

This responsible disclosure policy is designed to identify and promptly address new vulnerabilities and security issues in the hardware, software, or services provided by Schmidiger GmbH. It is based on the EU Cyber Resilience Act (CRA).

 

Scope

Security vulnerabilities in all products and services provided by Schmidiger GmbH can be reported through this reporting channel.

 

Reporting a Vulnerability

If you have discovered a potential security vulnerability in a Schmidiger product or service, we ask that you report it responsibly. Please use the form below to do so. Please include as much information as possible in your message, in German or English:

  • Affected product or system
  • Software/firmware version
  • Detailed description of the vulnerability (with evidence, if possible)
  • Steps to reproduce the vulnerability
  • Impact of the vulnerability (if known)
  • Your contact information and how to reach you

 

Our Process

  • We will confirm receipt of the report promptly.
  • We will review and assess the reported vulnerability.
  • If necessary, we will contact you with questions or to request additional information.
  • Depending on the nature and severity of the vulnerability, we take appropriate measures to address it and, if necessary, notify affected customers and/or the relevant authorities.

 

Responsible Disclosure

We ask that you:

  • refrain from unauthorized access to data,
  • do not modify or delete any data,
  • do not intentionally disrupt any systems,
  • not to disclose information about the vulnerability publicly before a solution is available.

Provided that you act in good faith, Schmidiger GmbH will not take legal action against security researchers who comply with this policy.

 

25 characters left
1000 characters left
1000 characters left
1000 characters left
Title
Address