Cybersecurity Vulnerability Reporting
Help us keep Engicam products secure
If you have identified a potential security vulnerability or incident affecting an Engicam product, we encourage you to report it to our security team.
Vulnerabilities and security incidents falling within the reporting obligations of Regulation (EU) 2024/2847 will be handled in accordance with the applicable requirements of the Cyber Resilience Act.
Report a security vulnerability
To report a security vulnerability, potential exploitation or security incident, please contact our security team:
Please provide as much technical information as possible to help us assess and address the issue.
What should you report?
- Product vulnerabilities: Suspected or confirmed security vulnerabilities affecting Engicam products.
- Potential exploitation: Information regarding the potential or confirmed exploitation of a vulnerability.
- Security incidents: Security incidents that may have an impact on the security of an Engicam product.
- Third-party components: Vulnerabilities affecting third-party components integrated into Engicam products.
- Other relevant information: Any other technical information that may help us assess and address a security issue.
Information to include
The more information you provide, the faster we can assess the issue.
Where available, please include:
- Product name (commercial name/code) and firmware version
- Description of the vulnerability
- Conditions required to reproduce the issue
- Technical evidence or proof of concept
- CVE or CWE identifier, if available
- Information regarding any known or suspected exploitation
- Observed or potential security impact
- Any mitigation or remediation measures already identified
Please do not include passwords, personal data or other sensitive information unless strictly necessary to assess the vulnerability.
What happens next?
01 — Report
You submit the vulnerability or security issue to our security team at security.cra@engicam.com.
02 — Assessment
Engicam will assess the information received and evaluate the relevance and potential impact of the reported issue.
03 — Remediation
Where applicable, Engicam will take appropriate mitigation and remediation measures.
Vulnerability management
Reported information will be handled in accordance with Engicam’s internal vulnerability management procedures.
Cyber Resilience Act
Engicam manages vulnerabilities and security incidents falling within the reporting obligations of Regulation (EU) 2024/2847 in accordance with the applicable requirements of the Cyber Resilience Act.
