MM-571470_cybersecurity_2000x2000.jpg

PSIRT – Vulnerability Disclosure Policy

This Policy is intended to provide researchers with clear guidelines for carrying out vulnerability discovery activities and our preferences for reporting vulnerabilities to us.

This Policy describes how you can send us vulnerability reports and how long we ask researchers to wait before disclosing vulnerabilities. We recommend contacting us to report potential vulnerabilities in our products.

For reports of product vulnerabilities, please email us at psirt@wago.com. Reports can be submitted anonymously.

Please use our public PGP key for confidential communication (see section “Reporting a Vulnerability”).

Authorization

If you make every effort in your research to comply with this Policy to the best of your knowledge and belief, we will consider your research authorized. We work with you to understand and solve the problem quickly.

Guidelines

“Research” in accordance with this Policy means activities in which you:

  • Notify us as soon as possible after uncovering an actual or potential security problem

  • Use exploits only to the extent necessary to confirm the existence of a vulnerability

  • Give us a reasonable amount of time to resolve the problem before you make it public

  • Do not submit a large volume of low-quality reports

Scope

WAGO does not limit the scope for products offered by WAGO, including hardware, software or components with digital elements. In the event of security vulnerabilities within our digital infrastructure, such as the WAGO website or any other type of service used by the company, please contact our Cyber Defense Center at the following email: cyberdefense@wago.com.

Reporting a Vulnerability

The information provided in this Policy is used exclusively for defensive purposes, i.e. to mitigate or eliminate vulnerabilities. Reports can be submitted anonymously. If you provide contact information, we will acknowledge receipt of your report. We support PGP encryption for email correspondence. The PGP key is accessible via our security.txt file. Please note that emails sent without PGP encryption may be ignored.

What We Would Like from You

To help us classify and prioritize potential vulnerabilities, please include the following in your report if possible:

  • Affected product or software version (item number, firmware version, etc.)

  • A description of where the vulnerability was discovered and the potential impact of the exploit

  • A detailed description of the steps required to replicate the vulnerability (proof-of-concept scripts or screenshots are helpful)

  • If available: related documents concerning vulnerability (CVE, announcements, release notes, etc.)

  • If possible, please write in English

What You Can Expect from Us

If you wish to share your contact data with us, we promise to coordinate with you as openly and quickly as possible.

  • We will confirm receipt of your report within one week.

  • Our team will analyze the report in collaboration with the development team or partners responsible.

  • We will inform you of the outcome of our investigation of your findings to the best of our knowledge and belief and explain the steps we take in the remediation process, including any problems or challenges that may delay a solution, as transparently as possible.

  • We will work with you to create a CVE entry (provided by our coordination partner CERT@VDE) and to ensure you receive adequate recognition for supporting the security of our products.

  • When we confirm the security vulnerability, we will inform our coordination partner cert@vde.

  • We will publicly disclose the problems you report once a solution is available or published (whichever comes first). The vulnerability will be published in the form of a security advisory in accordance with the CSAF 2.0 standard.

  • The vulnerability will be published through our coordination partner cert@vde.

  • We will engage in an open dialog to address any questions.

Questions

Questions about this Policy can be sent to psirt@wago.com. We also invite you to contact us with suggestions for improving this Policy.

Version
Date
Description

1.0

2025-06-11

First publication

WAGO Cybersecurity Instructions: We will gladly answer your questions.

kontaktmodul_kundenservice_zentrale_300x300_1

Main Office

Mon-Thu 8 am - 5 pm CET

Fri 8 am - 3 pm CET

Additional service offerings: