konfo_Header-small.jpg

ADS-TEC Coordinated Vulnerability Disclosure

Reporting security vulnerabilities responsibly

The security of our products is our top priority. Should you discover a potential security vulnerability in an ADS-TEC Industrial IT product, we would be grateful if you could report it to us. Together with security researchers and customers, we ensure that reported vulnerabilities are addressed in a coordinated and responsible manner.

Coordinated Vulnerability Disclosure Policy

With our Coordinated Vulnerability Disclosure (CVD) Policy, we have established a clearly defined process for reporting, assessing and rectifying security vulnerabilities.

The policy applies to all hardware and software products developed and distributed by ADS-TEC Industrial IT, including firmware and accessory software. Products that have reached the End-of-Life (EOL) status officially announced by ADS-TEC Industrial IT are excluded from the scope of this policy. We also accept reports of vulnerabilities affecting third-party components used in our products. These reports are forwarded to the relevant manufacturer, while we coordinate the further handling of the issue and keep the reporting party informed of any significant progress.

Reporting a vulnerability

Have you discovered a potential security vulnerability? Please send your report directly to our Product Security Incident Response Team (PSIRT).

Email address for security reports

psirt@ads-tec.de

Machine-readable contact details

Our contact details for security reports are also available in the security.txt file.

security.txt

Encrypted communication

We provide a public PGP key for confidential communication.

Download PGP key

Anonymous Reporting

You may also report vulnerabilities anonymously. Reports are accepted even if a secure communication channel cannot be used.

Your report should ideally include

  • The affected product and version number
  • A description of the vulnerability and its potential impact
  • Steps to reproduce the issue
  • Optionally, a proof of concept (which will, of course, be treated confidentially)

Alternative reporting channel

Alternatively, vulnerabilities can also be reported via our CERT@VDE profile.

Open CERT@VDE profile

Our Process

Every report we receive is assessed by our Product Security Incident Response Team. Our aim is to process reports quickly and to maintain transparent communication throughout the Coordinated Vulnerability Disclosure process.

StepTimeframe
Acknowledgement of receipt with a unique tracking ID5 working days
Initial assessment (CVSS score, affected versions)20 working days
Target remediation time – critical (CVSS ≥ 9.0)30 days
Target remediation time – high/medium (CVSS 4.0 – 8.9)90 days
Target remediation time – low (CVSS < 4.0)Regular update cycle
Co-ordinated releaseFollowing patch deployment

In the case of particularly complex vulnerabilities, or where multiple vendors are affected (multi-party CVD), these deadlines may be extended in consultation with the reporter. We will, of course, proactively inform the reporter of any changes in status.

Disclosure Policy & Embargo

We follow the principle of Coordinated Vulnerability Disclosure (CVD). Vulnerability details are only disclosed once a fix is available. The embargo period is generally up to 90 days. For particularly complex vulnerabilities or where multiple vendors are affected (multi-party CVD), this period may be extended in agreement with the reporting party.

Security Advisories

Once a vulnerability has been remediated, we publish a human-readable Security Advisory via our CERT@VDE profile. We also provide the information in the machine-readable CSAF (Common Security Advisory Framework) format.

Latest Security Bulletins, Patches and Advisories

Open CERT advisories
 
Upon request, we will name reporters who adhere to the coordinated disclosure process in the relevant security advisory.

Safe Harbor

We welcome the responsible reporting of security vulnerabilities and will not take legal action against individuals who report vulnerabilities in good faith and in accordance with our CVD Policy.

This is subject to the following conditions:

  • no data is accessed, altered or deleted without authorisation,
  • no damage is caused to systems or services,
  • the vulnerability is treated as confidential until a security update is made available or the mutually agreed embargo period has expired,
  • no confidential information is disclosed to third parties.