Reporting security vulnerabilities
If you have discovered a potential security vulnerability in a SYS TEC electronic product, software component, piece of documentation or on the SYS TEC electronic website, you can report it via the relevant PSIRT. On this page, you will find the contact details, recommended information to include in your report, details on encrypted transmission, and the process for handling and disclosing reported vulnerabilities.
At SYS TEC electronic, we attach great importance to the security of our products. Nevertheless, it is widely recognised that no product or customer system can be 100% secure, regardless of how much effort is invested in product security. SYS TEC electronic therefore wishes to be informed of any potential security issues affecting our products so that we can take the necessary measures as quickly as possible and rectify any vulnerabilities without delay. The Product Security Incident Response Team, or PSIRT for short, oversees the process of receiving and handling reports of potential security vulnerabilities in our products, including hardware, software and documentation.
The Computer Security Incident Response Team (CSIRT) at SYS TEC electronic AG is responsible for internal matters and the website.
How to report a potential security vulnerability
You can contact the SYS TEC electronic PSIRT at psirt@systec-electronic.com and our CSIRT at csirt@systec-electronic.com to report a potential security vulnerability. Your report should be written in German or English. SYS TEC electronic will send you a confirmation of receipt for your email as soon as possible.
Information regarding security vulnerabilities is highly sensitive. We strongly recommend that all submitted security vulnerability reports be sent in encrypted form using the SYS TEC electronic PGP/GPG key: SYS TEC electronic PGP/GPG key
What information your report should contain
To help us assess the potential security vulnerability, we recommend that you provide the following information:
- Potentially affected hardware or software products (including version or revision)
- How and when the potential vulnerability was discovered, and by whom
- Technical description of the potential security vulnerability, where already known, including all associated (1) known exploits and (2) existing CVE IDs
- Your contact details, so that our teams can ask you further questions if necessary
Process for handling reports
Once a report has been submitted, SYS TEC electronic follows the process below to assess the potential security vulnerability and respond to it:
- Notification: SYS TEC electronic becomes aware of a potential security vulnerability.
- Initial assessment: SYS TEC electronic reviews the report to determine whether a SYS TEC electronic product or service may be affected and whether sufficient information has been provided.
- Technical analysis: SYS TEC electronic investigates the reported potential security vulnerability in more detail.
- Remediation: SYS TEC electronic takes appropriate measures to address confirmed security vulnerabilities in its products and services.
- Disclosure: Where appropriate, SYS TEC electronic discloses information about the confirmed security vulnerability and makes the remedial measures available.
Responsible Disclosure Policy
Like most companies in the technology sector, SYS TEC electronic follows a Responsible Disclosure Policy. Our policy outlines what you can expect from SYS TEC electronic and what we expect from you. It is based on the CERT® Guide to Coordinated Vulnerability Disclosure. Before submitting a report, please read through our policy, as it sets out the basis of our relationship with you.
Get in touch now
Your contact person: Ihr CSIRT-Team der SYS TEC electronic
Department: We're happy to help:
Email: csirt@systec-electronic.comPhone: +49 3765 38600 0
Your contact person: Ihr PSIRT-Team der SYS TEC electronic
Department: We're happy to help:
Email: psirt@systec-electronic.comPhone: +49 3765 38600 0