Coordinated Vulnerability Disclosure (CVD) Policy

 At Fabmatics, the security of our products and automation solutions is our top priority. We value the work of security researchers, customers, and partners who help make our hardware and software products more secure. This policy outlines how you can report vulnerabilities in our products to us and the steps we take during the analysis and remediation process.

1. Scope

This policy applies to all products and services developed and distributed by Fabmatics, in particular:

  • Hardware and automation components
  • Firmware, drivers, and operating software
  • Engineering software, programming tools, and mobile apps
  • Publicly accessible cloud services and online infrastructures

Out of Scope:

  • Physical attacks against buildings, data centers, or customer systems
  • Denial-of-Service attacks (DoS/DDoS) against our services or our customers' production facilities
  • Social engineering attacks (e.g., phishing) against employees or customers
  • Vulnerabilities in third-party components without a direct integration context to our products (please report directly to the respective manufacturer)

 2. Code of Conduct for Reporters (Safe Harbor)

 We commit to not taking any legal action against you as long as you act in good faith and adhere to the following principles:

  • No Harm: Do not perform any actions that compromise the availability or integrity of our systems or our customers' facilities.
  • Data Privacy: Do not access third-party or confidential customer data. If you encounter data during your research, stop the process and delete any local copies immediately.
  • Confidentiality: Keep information about the vulnerability confidential until we have analyzed the vulnerability, provided a patch or workaround, and agreed upon the coordinated disclosure.
  • No Extortion: Do not tie the disclosure to financial demands outside of official bug bounty programs.

3. How to Report a Vulnerability

Submit your findings to our Product Security Incident Response Team (PSIRT):

 Required Information:

  • Affected product, model name, and firmware/software version.
  • Detailed description of the vulnerability, including Proof-of-Concept (PoC), screenshots, log files, or steps to reproduce.
  • Your assessment of the potential impact and risks.
  • Any indications as to whether the vulnerability is already being actively exploited, to your knowledge.

4. Our Process and Processing Commitments

Upon receipt of a report, it goes through the following phases:

  • Acknowledgment of Receipt: You will receive confirmation of the receipt of your report within 5 business days.
  • Triage and Validation: Our PSIRT assesses the vulnerability and checks the impact on our product portfolio. We will keep you regularly informed about the status.
  • Remediation: We prioritize developing a firmware update, a software patch, or documented mitigating actions (workarounds).
  • Coordinated Disclosure: Once the protective measures are finalized, we publish a Security Advisory and notify affected customers.
  • Regulatory Reporting: Where required by law, actively exploited vulnerabilities and severe security incidents will be reported to the relevant authorities within the specified timeframes.

 

Issue a Report