Product security and vulnerability reporting
This page contains the public version of our Coordinated Vulnerability Disclosure (CVD) policy. It is intended for security researchers, customers, and anyone who has discovered a potential security vulnerability in a PANTEC Engineering AG product.
What you should report
Please report any vulnerability that could compromise the security of a PANTEC product with digital components, for example:
- Vulnerabilities in firmware or embedded software
- Insecure default configurations
- Authentication or authorization issues
How to report a vulnerability
Contact: security@pantec.com
Please include the following in your report, if possible:
- Affected product and version/serial number, if known
- Description of the vulnerability and steps to reproduce it
- Potential impact (to the extent you can assess them)
- Your contact information for follow-up questions
Information to provide
Product
- Product name, type, and part number
- Serial or manufacturing number
- Firmware, bootloader, and software versions
- Affected interface (e.g., Ethernet, EtherCAT, CAN, USB, RS-232)
- Relevant hardware configuration
Vulnerability
- Description and potential impact
- Steps to reproduce the issue
- Required access (network, local, physical) and necessary equipment
- Whether you observed the vulnerability in a production environment
- Whether you have evidence that the vulnerability is already being actively exploited
- Suggestions for remediation or workarounds, if known
Additional Information
- Logs, traces, diagnostic output, screenshots, network captures
- Proof-of-concept code or commands
- Your contact information and whether or how you would like to be credited
Please send personal data, access credentials, cryptographic keys, or customer data only if they are absolutely necessary for the analysis.
What you can expect from us
- Confirmation of receipt: within 3 business days
- Verification of whether a PANTEC product is affected, and possible follow-up questions for you: within 10 business days
- Target resolution time: depending on the severity, in accordance with our internal vulnerability management policy. We will keep you updated on our progress.
Coordinated disclosure
We ask that you refrain from publishing information about a reported vulnerability until a fix or workaround is available or until we have agreed on a disclosure date with you. As a general guideline, we aim for coordinated disclosure within 120 days of your report, depending on the complexity of the fix.
Rules for reporters
To protect our customers and their equipment, we ask that you:
- Test only on your own equipment or with the express consent of the owner or operator
- Do not endanger any persons, machines, or production processes; when testing equipment with connected drives, do so only with secured axes or without a load
- Do not access third-party data and do not modify or delete any data, except to the extent absolutely necessary for verification
- Do not perform denial-of-service tests against production systems
- Exploit the vulnerability only to the extent necessary to demonstrate it
- Treat information about the vulnerability as confidential until we have agreed on a disclosure date with you
- Comply with applicable laws
Disclosure and recognicion
PANTEC does not currently operate a bug bounty program. Submitting a report does not entitle you to a reward.
Contact
Please send any questions about this policy to security@pantec.com. We also welcome suggestions for improving this policy.
