ADS-TEC Coordinated Vulnerability Disclosure
Reporting security vulnerabilities responsibly
The security of our products is our top priority. Should you discover a potential security vulnerability in an ADS-TEC Industrial IT product, we would be grateful if you could report it to us. Together with security researchers and customers, we ensure that reported vulnerabilities are addressed in a coordinated and responsible manner.
Coordinated Vulnerability Disclosure Policy
With our Coordinated Vulnerability Disclosure (CVD) Policy, we have established a clearly defined process for reporting, assessing and rectifying security vulnerabilities.
The policy applies to all hardware and software products developed and distributed by ADS-TEC Industrial IT, including firmware and accessory software. Products that have reached the End-of-Life (EOL) status officially announced by ADS-TEC Industrial IT are excluded from the scope of this policy. We also accept reports of vulnerabilities affecting third-party components used in our products. These reports are forwarded to the relevant manufacturer, while we coordinate the further handling of the issue and keep the reporting party informed of any significant progress.
Reporting a vulnerability
Have you discovered a potential security vulnerability? Please send your report directly to our Product Security Incident Response Team (PSIRT).
Email address for security reports
Machine-readable contact details
Our contact details for security reports are also available in the security.txt file.
Encrypted communication
We provide a public PGP key for confidential communication.
Anonymous Reporting
You may also report vulnerabilities anonymously. Reports are accepted even if a secure communication channel cannot be used.
Your report should ideally include
- The affected product and version number
- A description of the vulnerability and its potential impact
- Steps to reproduce the issue
- Optionally, a proof of concept (which will, of course, be treated confidentially)
Alternative reporting channel
Alternatively, vulnerabilities can also be reported via our CERT@VDE profile.
Our Process
Every report we receive is assessed by our Product Security Incident Response Team. Our aim is to process reports quickly and to maintain transparent communication throughout the Coordinated Vulnerability Disclosure process.
| Step | Timeframe |
| Acknowledgement of receipt with a unique tracking ID | 5 working days |
| Initial assessment (CVSS score, affected versions) | 20 working days |
| Target remediation time – critical (CVSS ≥ 9.0) | 30 days |
| Target remediation time – high/medium (CVSS 4.0 – 8.9) | 90 days |
| Target remediation time – low (CVSS < 4.0) | Regular update cycle |
| Co-ordinated release | Following patch deployment |
In the case of particularly complex vulnerabilities, or where multiple vendors are affected (multi-party CVD), these deadlines may be extended in consultation with the reporter. We will, of course, proactively inform the reporter of any changes in status.
Disclosure Policy & Embargo
We follow the principle of Coordinated Vulnerability Disclosure (CVD). Vulnerability details are only disclosed once a fix is available. The embargo period is generally up to 90 days. For particularly complex vulnerabilities or where multiple vendors are affected (multi-party CVD), this period may be extended in agreement with the reporting party.
Security Advisories
Once a vulnerability has been remediated, we publish a human-readable Security Advisory via our CERT@VDE profile. We also provide the information in the machine-readable CSAF (Common Security Advisory Framework) format.
Latest Security Bulletins, Patches and Advisories
Open CERT advisories
Upon request, we will name reporters who adhere to the coordinated disclosure process in the relevant security advisory.
Safe Harbor
We welcome the responsible reporting of security vulnerabilities and will not take legal action against individuals who report vulnerabilities in good faith and in accordance with our CVD Policy.
This is subject to the following conditions:
- no data is accessed, altered or deleted without authorisation,
- no damage is caused to systems or services,
- the vulnerability is treated as confidential until a security update is made available or the mutually agreed embargo period has expired,
- no confidential information is disclosed to third parties.