Coordinated Vulnerability Disclosure Policy HEITEC
HEITEC AG
1. Introduction
HEITEC AG is committed to the protection of the security of our products, services and data. We value the contributions of security researchers and the wider community in identifying vulnerabilities and helping us improve our security posture.
With that purpose in mind, and with regard to the requirements of the Regulation (EU) 2024/2847 (Cyber Resilience Act), we have set a Coordinated Vulnerability Disclosure Policy in accordance with the BSI guidelines and recommendations.
2. Scope
This policy applies to:
- All digital assets owned, operated or maintained by HEITEC AG
- Products and services provided by HEITEC AG
- Customer-owned products and systems for which HEITEC AG has been contractually assigned responsibility for vulnerability management.
The following attacks and vulnerabilities are outside the scope of this policy:
- Social engineering attacks.
- Physical attacks on HEITEC AG property or personnel.
- Denial of Service (DoS) attacks.
- Vulnerabilities in third-party products not owned by HEITEC AG.
- Vulnerabilities found as a result of automated tools or scans without supporting documentation
3. Reporting a vulnerability
If you believe you have discovered a security vulnerability, please report it to us as soon as possible by sending an Email to the addresses listed blow.
Please include:
- A detailed description of the vulnerability.
- Specific model, versions and/or configuration affected
- Steps to reproduce the issue.
- Any relevant screenshots or proof-of-concept code.
- Your contact information for follow-up, preferrable via Email or Telephone.
If you prefer to stay anonymous, communication will not be continued by HEITEC AG. Please consider that, in that case, the vulnerability reports may be limited.
4. Safe Harbor
HEITEC AG will not pursue legal action against individuals who:
- Act in good faith to report vulnerabilities.
- Follow the guidelines outlined in this policy
- Avoid violating privacy, destroying data, or interrupting services.
- Do not access or modify data that does not belong to them.
- Agree with the disclosure practices defined in the section below.
- Comply with all applicable laws.
HEITEC AG is committed to ensuring the confidentiality of your report to the extent permitted by law.
5. Our commitment
Upon receiving your report, HEITEC AG will:
- Acknowledge receipt of your report within 5 business days.
- Work with you to understand and validate the issue.
- Strive to resolve the vulnerability promptly.
- Ensure that all reports are analyzed and processed thoroughly
- Keep you informed, as appropriate and practicable, of significant progress and expected timelines throughout the CVD process.
- Notify the corresponding national CSIRT, to the extent required by law, according to the requirements of the Cyber Resilience Act
- Disclose the vulnerability publicly when required by law or when deemed appropriate in individual cases, and always in coordination with the relevant CSIRT and/or ENISA. If applicable, the vulnerability will be published, at minimum, on the European Vulnerability Database (EUVD).
The CVD will be completed once the vulnerability is publicly disclosed and a remediation solution has been made available.
6. Contact
Corporate Security Incidents (CSIRT):
For incidents affecting our corporate IT infrastructure: csirt@heitec.de
Product Vulnerability Reports (PSIRT):
For reporting security vulnerabilities in our products: psirt@heitec.de
For confidential communication, we recommend using our PGP keys, which can be found at https://www.heitec.de/.well-known/security.txt.