Version 1.0, 2012-06-08
Siemens ProductCERT publishes security vulnerabilities that have been fixed within our products through security advisories containing detailed information about the issues.
A vulnerability handling process typically consists of the following four steps at Siemens:
1. Report
The vulnerability is reported by an external party to Siemens ProductCERT. Please contact us using the ways described in Section “Contact Information”. We respond to incoming reports within one work day.
Please report the following information:
Everyone is encouraged to report discovered vulnerabilities, regardless of service contracts or product lifecycle status. We welcome vulnerability reports directly from researchers, industry groups, CERTs, partners and any other source as we do not require a non-disclosure-agreement for the report to be in place. We respect the interests of the reporting party (also anonymous reports if requested) and agree to handle any vulnerability that is reasonably believed to be related to our products or services. We strongly urge reporting parties to perform a coordinated disclosure, as immediate public disclosure causes a ‘0-day situation’ which puts our customers’ systems at unnecessary risk. Those systems comprise significant parts of the worldwide critical infrastructure.
2. Analysis
Siemens ProductCERT internally investigates and reproduces the vulnerability. If needed, we request more information from the reporter.
3. Handling
Siemens ProductCERT performs internal vulnerability handling in collaboration with the responsible development groups. CERT teams having a partnership with us may be notified about the problem upfront.
During this time, regular communication is maintained between Siemens ProductCERT and the reporting party to inform about the current status and to ensure that the vendor’s position is understood by the reporting party. If available, pre-releases of software fixes may be provided to the reporting party for verification.
4. Disclosure
After the issue was successfully analyzed and corresponding fixes have been integrated in the product and are ready for distribution, Siemens ProductCERT releases an advisory that contains all necessary information on our website (see Section “Contact Information” below).
The advisory usually contains the following information:
Contact Information
Website: http://www.siemens.com/cert/advisories
Email:
- Checked 7 days a week, response within one work day
- Public PGP and S/MIME keys are available
Version Date Description
1.0 2012-06-08 Publication