[{"url":"/products","name":"Products","linkClass":null,"categoryCode":null},{"url":"/automation-technology","name":"Automation Technology","linkClass":null,"categoryCode":null},{"url":"/automation-technology/psirt","name":"Security Instructions – PSIRT","linkClass":null,"categoryCode":null},{"url":"/automation-technology/psirt/vulnerability-disclosure-policy","name":"Vulnerability Disclosure Policy","linkClass":"active","categoryCode":null}]
PSIRT – Vulnerability Disclosure Policy
This Policy is intended to provide researchers with clear guidelines for carrying out vulnerability discovery activities and our preferences for reporting vulnerabilities to us.
This Policy describes how you can send us vulnerability reports and how long we ask researchers to wait before disclosing vulnerabilities. We recommend contacting us to report potential vulnerabilities in our products.
For reports of product vulnerabilities, please email us at psirt@wago.com. Reports can be submitted anonymously.
Please use our public PGP key for confidential communication (see section “Reporting a Vulnerability”).
Authorization
If you make every effort in your research to comply with this Policy to the best of your knowledge and belief, we will consider your research authorized. We work with you to understand and solve the problem quickly.
Guidelines
“Research” in accordance with this Policy means activities in which you:
- Notify us as soon as possible after uncovering an actual or potential security problem
- Use exploits only to the extent necessary to confirm the existence of a vulnerability
- Give us a reasonable amount of time to resolve the problem before you make it public
- Do not submit a large volume of low-quality reports