Vulnerability Disclosure Policy

Reporting Security Vulnerabilities
 

The security of our machines, control systems, software products and digital components is of high importance to us.

We welcome reports of potential vulnerabilities and handle them through a defined process managed by our PSIRT (Product Security Incident Response Team).

This policy applies to products with digital elements provided by us, in particular during the applicable support period.
 

Reporting a Vulnerability

Vulnerabilities may be reported by customers, security researchers, suppliers and other third parties.
 

Contact:
Email: product-security(at)dorst.de
 

Reports may be submitted in German or English. Anonymous reports are also accepted.

A NDA (Non-Disclosure Agreement) is not required in order to report a vulnerability.

 

What Information Should a Report Include?

A vulnerability report should, where possible, include the following information:

  • affected product, machine or component 
  • product, software or firmware version 
  • description of the vulnerability 
  • potential impact 
  • technical evidence, such as screenshots, log files or a PoC (Proof of Concept) 
  • information on whether the vulnerability has already been publicly disclosed 
  • contact information for follow-up questions 
     

Coordinated Vulnerability Disclosure (CVD)

We support the coordinated disclosure of vulnerabilities in accordance with the principles of CVD.

We ask reporters in particular to:

  • perform only those tests that are necessary to demonstrate the vulnerability, 
  • not access, copy, modify or delete data belonging to third parties, 
  • not disrupt machines, industrial installations or services, 
  • not unnecessarily bypass security mechanisms, 
  • not endanger the safety of persons, machines or industrial installations
  • keep information about the vulnerability confidential until coordinated disclosure has taken place. 

Testing machines or industrial installations operated by our customers is only permitted with the consent of the respective operating company.

Reporting a vulnerability to us does not constitute authorization to perform penetration testing on customer installations or third-party systems.

We do not intend to pursue legal action solely on the basis of responsible security research against individuals who act in good faith, comply with these principles and comply with applicable law.
 

How We Handle Vulnerability Reports
 

Our PSIRT (Product Security Incident Response Team) handles vulnerability reports through a defined process.

1. Receipt

We register the vulnerability report and acknowledge receipt.

2. Analysis

We analyze the reported vulnerability, identify the affected product or products with digital elements and assess the potential impact.

Where necessary, we contact the reporter for additional information.

3. Remediation

Together with the responsible product and development teams, we evaluate appropriate remediation or mitigation measures.

These may include, for example:

  • a security update or patch, 
  • a configuration change, 
  • a workaround, or 
  • additional protective or mitigation measures. 

4. Disclosure

Where required and appropriate, we provide information about fixed vulnerabilities and necessary customer actions through our Security Advisories (security notices).

 

To our → Security Advisories

 

Security Advisories may include information about affected products and versions, the potential impact of a vulnerability, available security updates, patches, workarounds or mitigation measures.

Disclosure is coordinated with the aim of minimizing risks to customers, machines and industrial installations.

Statutory Reporting Obligations

Where required by law, we fulfil our reporting obligations under the CRA (Cyber Resilience Act – Regulation (EU) 2024/2847).

In particular, where the applicable legal requirements are met, actively exploited vulnerabilities and severe incidents having an impact on the security of products with digital elements are reported through the applicable reporting channels, including the ENISA (European Union Agency for Cybersecurity) Single Reporting Platform (SRP).

Statutory reporting to the competent authorities and the publication of a Security Advisory are separate processes and must be assessed independently.

Confidentiality and Data Protection

Vulnerability reports are treated confidentially.

Personal data is processed and disclosed only to the extent necessary for handling the vulnerability or where required by applicable law.

No Bug Bounty Program

Unless explicitly stated otherwise, we do not operate a Bug Bounty Program (a program providing rewards for reporting qualifying security vulnerabilities).

Therefore, reporting a vulnerability does not generally create any entitlement to financial compensation, rewards or other consideration.

Contact

Do you have any questions?
We are glad to be at your service.