E+E Product Security Incident Response Team
The E+E Product Security Incident Response Team (PSIRT) serves as the central point of contact for reporting, investigating, and coordinating the disclosure of security vulnerabilities affecting E+E Elektronik products.
Product security is an integral part of our commitment to quality, beginning with product development and extending throughout the entire product lifecycle.
We welcome vulnerability reports from the security community, customers, research institutions, public authorities, and business partners, regardless of whether a contractual customer relationship exists.
Scope
The E+E PSIRT handles vulnerability reports related to all E+E Elektronik products with digital elements. This includes hardware, firmware, associated configuration and evaluation software, as well as cloud-based services where applicable.
For discontinued products ("End of Life"), security advisories will continue to be published for at least five years after the end of market placement. The patch status of affected products is transparently communicated in each advisory.
Reporting a vulnerability
If you have reason to believe that you have discovered a security vulnerability in one of our products, please submit your report via email to our PSIRT.
| psirt(at)epluse.com | |
| PGP-Fingerprint | C568 9FB4 5292 DEC2 05BE F7E5 78F7 4FEC 36B8 CC4B |
| PGP Public Key | Download |
| Languages | German, English |
| Transmission | Encrypted communication preferred |
To protect sensitive information, we strongly recommend submitting reports in encrypted form. Suitable tools include Gpg4win or GnuPG.
Neither a Non-Disclosure Agreement (NDA) nor any other contractual arrangement is required for vulnerability reporting and collaboration.
Please note that psirt(at)epluse.com is intended exclusively for reports of security-related vulnerabilities.
For general product inquiries, technical support, or complaints, please contact our customer service team.
Information Required
To enable efficient assessment and handling of your report, please include the following information whenever possible:
- Contact details (name, organization, email address, optional telephone number)
- Affected product, including model designation, hardware revision, and firmware/software version
- Vulnerability classification (e.g., CWE ID, CVE ID, if available)
- Detailed technical description, ideally including a proof of concept or reproduction steps
- Expected impact and attack prerequisites
- CVSS v4.0 score (if already assessed)
- Current dissemination status of the information and any planned disclosure activities
Should additional information be required during the investigation, we will contact you accordingly.
What happens after you submit a report
Reports are processed exclusively by authorized members of the E+E PSIRT.
The identity and contact information of reporters are treated confidentially and will not be disclosed in public communications unless explicitly requested.
Response Times
We aim to provide:
- Acknowledgement of receipt within 3 business days
- Initial technical assessment and feedback within 10 business days
- Regular status updates throughout the investigation process until publication of a security advisory
Vulnerability Handling Process
- Report Submission: We acknowledge receipt of the report and perform an initial review.
- Analysis: We investigate the reported issue to determine whether a security vulnerability exists.
During this phase, we may contact you if additional information or clarification is required. - Remediation: We evaluate and implement appropriate corrective or mitigating measures to address confirmed vulnerabilities.
- Disclosure: Once a fix or mitigation is available, we inform the reporter and, where appropriate, other stakeholders.
A Security Advisory is then published.
Coordinated Vulnerability Disclosure
E+E Elektronik follows the principles of Coordinated Vulnerability Disclosure (CVD) in alignment with ISO/IEC 29147 (Vulnerability Disclosure) and ISO/IEC 30111 (Vulnerability Handling Processes).
Our objective is to ensure that affected users have access to a remediation or effective mitigation measures before details of a vulnerability are publicly disclosed.
As a general guideline, we seek to agree with reporters on a disclosure timeline of 90 calendar days from the date of initial reporting.
Where justified, for example due to remediation complexity or extensive deployment requirements, this period may be extended by mutual agreement.
In cases where vulnerabilities are actively exploited in the wild, we may publish mitigation guidance at an earlier stage, even if a complete solution is not yet available.
We kindly ask reporters to refrain from unilateral public disclosure while coordinated disclosure activities are ongoing.
Recognition of Reporters
We highly value the contributions of the security community.
Upon request, reporters will be acknowledged by name following successful coordinated disclosure.
E+E Elektronik does not currently operate a monetary bug bounty program.
Security Advisories
Confirmed vulnerabilities are published as Security Advisories on this website as soon as a remediation or effective risk mitigation becomes available.
Where the risk situation requires immediate action, we may publish protective guidance before a software update or patch is available.
Each Security Advisory includes at least:
- Unique Advisory ID
- Affected products and versions
- Description of the vulnerability and potential impact
- CVSS v4.0 score and CVSS vector
- Available remediation or recommended mitigation measures
- Acknowledgement of the reporter (upon request)
