Promicon Systems

Cyber-Security

Promicon PSIRT

The Promicon PSIRT was established to address security issues (incidents and vulnerabilities) that may arise in Promicon products. Promicon is committed to proactively addressing potential vulnerabilities in our products. As part of our process, we have established Promicon PSIRT as our point of contact for product safety. You can find our policy for the coordinated disclosure of vulnerabilities at CVD (Coordinated Vulnerability Disclosure) - Policy, and we ask that you read and follow them.

Disclosure of information on vulnerabilities

Promicon publishes security advisories regarding the affected products based on coordinated vulnerability disclosure to ensure that the vulnerabilities are addressed while minimizing risk and that users have sufficient information to assess the risks to their systems. Safety notices therefore do not constitute a comprehensive list of incidents.

Reporting vulnerabilities

Please send the information regarding the potential vulnerability to the Promicon PSIRT.

Promicon PSIRT


To enable the Promicon PSIRT to address the potential vulnerability, please provide the following information:

  • Full product name and the affected component
  • Hardware and software version numbers for all components involved
  • Date and time of the incident
  • Detailed description of the vulnerability
    • Technical details (such as system configuration, log data, and a description of the exploit/attack code)
    • Detailed step-by-step guide to reproducing the vulnerability
    • Attachments that help reproduce the issue, such as images, videos, scripts, and payloads
    • Proof-of-Concept-Code, if available
  • Assessment of the severity of the vulnerability
  • Impact of the vulnerability, including how an attacker could exploit it
  • Your contact information—we respect anonymous reports

The information should be provided in German or English.
Insufficient information may result in the Promicon PSIRT being unable to confirm the information.

Promicon recommends that the person submitting the report encrypt any sensitive information sent via email. The Promicon PSIRT supports messages encrypted using the OpenPGP standard. Please send us your PGP key so that Promicon PSIRT can reply to you securely.

PGP-Key
Fingerprint 5A16 A400 4D72 165F 4600 4A26 7D69 C563 DC5B 2001
Key Public key

Important Information

  • We process only information regarding potential vulnerabilities affecting Promicon products.
  • Anonymous reports can only be processed to a limited extent, or possibly not at all, because there is no way to ask follow-up questions regarding technical details or content.
  • We will use your contact information solely for the purpose of analyzing and identifying potential vulnerabilities.
  • To protect our customers, we ask that you not disclose this vulnerability to other individuals or organizations without first consulting with the Promicon PSIRT.


Security Advisories

None available.



top