Link per E-Mail teilen
Es wurden nicht alle notwendigen Felder befüllt.
E-Mail senden

Coordinated Vulnerability Disclosure Policy

Detailed information on the scope and reporting options

Introduction

The Bürkert Group believes that strong security is built on collaboration. This Coordinated Vulnerability Disclosure (CVD) Policy provides a clear and reliable framework that encourages security researchers, customers, and partners to actively contribute to the security of our products and digital infrastructure.

Our objective is to create an environment where security researchers feel empowered to investigate and report vulnerabilities responsibly and in good faith. To achieve this, we:

  • Provide clear processes and communication channels for reporting and handling vulnerabilities in a structured and secure manner.
  • Offer legal assurances and recognition to researchers who act responsibly, ensuring they can contribute without fear of legal repercussions.
  • Promote transparency and trust through coordinated disclosure and timely remediation of identified issues.

This policy defines the scope of testing, reporting guidelines, and the company’s commitments. It ensures that vulnerabilities are addressed efficiently and disclosed in a way that protects our customers and strengthens the overall security posture of the Bürkert Group. It is reviewed regularly and updated as necessary to reflect evolving security practices, technological developments, and organizational requirements.

 

Authorization

Bürkert hereby authorizes security testing only of systems and products explicitly listed as "In Scope" and only in accordance with this policy. Any activity outside these boundaries is not authorized. Authorization is automatically revoked upon any breach of this policy. 

 

Scope

Only conduct security testing and vulnerability reporting for products and infrastructures of the Bürkert Group that fall within the scope of this policy. Testing systems or using methods that are Out of Scope is strictly prohibited. 

In Scope

  • Bürkert Group products (e.g., hardware components, software applications, mobile apps).
  • Bürkert digital infrastructure and services (e.g., websites, networks, APIs)  

Out of Scope (non-exhaustive)

  • Third‑party systems or products (e.g., cloud providers not part of the Bürkert Group, or customer installations without written approval).
  • Denial‑of‑Service attacks (DoS/DDoS).
  • Brute‑force attacks.
  • Social engineering activities (e.g., phishing, vishing).
  • Physical security testing (e.g., access controls).
  • Issues without security impact (e.g., UI/UX bugs). 

Note: The scope of any Bug Bounty Program may differ from this policy. Refer to the current Bürkert Bug Bounty Program for details.

 

Reporting options

If you have discovered a vulnerability in a product or digital service of the Bürkert Group, please report it via one of the following channels: 

Your report should include:

  • Affected system or product (including version).
  • Description of the vulnerability and its impact.
  • Steps to reproduce (e.g., screenshots, proof‑of‑concept scripts) — please provide minimal PoC sufficient to demonstrate impact.
  • Your name, organization, and email address (strongly recommended, but anonymous reports are accepted). 

We recommend using PGP‑encrypted communication for sensitive information. Our public keys are available in our /.well-known/security. txt. Please include your public key so we can respond securely.

If personal data is transmitted with a report, please note our privacy policy. If you inadvertently access any personal or third‑party data, follow the rules and notify us immediately. 
 

Reporter guidelines

To ensure a secure and constructive CVD process, you must follow these principles:

  • Act lawfully: Comply with all applicable laws and regulations during your research and reporting.
  • Respect scope and avoid harm: Do not test or use systems or methods that are explicitly marked as out of scope (see chapter Scope). Avoid any actions that may lead to privacy violations, service disruptions, data loss, or degradation of user experience. Ensure that the testing is carried out with the utmost care and using secure technical methods in order to prevent any data leakage.
  • Do not exploit vulnerabilities beyond what is necessary for verification: Do not misuse vulnerabilities to cause harm to Bürkert, its customers, or third parties. Accessing, modifying, or disclosing personal or confidential information (e.g., PII) is strictly prohibited. Do not submit weaponized exploits or automation enabling mass exploitation.
  • No unauthorized data access or exfiltration: Do not access, copy, store, transfer, or disclose personal data or third‑party data. If unintentionally accessed, stop, minimize further access, and report immediately.
  • No external sharing: Keep all information about the vulnerability confidential between you and the official reporting channels of the Bürkert Group until the issue has been resolved. Do not publish or share details without prior agreement. Support or assist third parties in committing exploitation is strictly prohibited. Sharing or distributing exploit tools and exploit information with third parties (whether paid or free) is not allowed before coordinated disclosure is completed.  
  • Submit high-quality reports: Submit vulnerabilities individually, unless multiple findings are technically dependent to demonstrate impact. Reports must contain previously unknown information. Already resolved vulnerabilities may be reviewed but are excluded from further processing.
  • Avoid low-value submissions: Do not submit results from automated scans or tools without sufficient documentation and explanation. Such submissions do not qualify as valid vulnerability reports.
  • No interception: Do not capture, monitor, or intercept network traffic other than your own test traffic to in‑scope assets. 

 

Company commitments

To ensure a transparent and effective CVD process, the Bürkert Group commits to the following:

  1. Timely response. We acknowledge receipt within 7 days and provide an initial assessment within 14 days.
  2. Communication. We provide periodic status updates and inform you when remediation or mitigation is completed.
  3. Remediation & disclosure. We aim to remediate validated vulnerabilities promptly and commit to publicly disclosing validated vulnerabilities in standard products within 90 days of validation (timeline may be extended where justified).
  4. Confidentiality. We treat your report confidentially within the limits of the law. Personal data will not be disclosed to third parties unless you give explicit consent or disclosure is legally required.
  5. Legal assurance / Safe Harbor. If you act in good faith and comply with this Policy, we will not pursue legal action or file criminal complaints against you for your research; we will treat your in‑scope testing as authorized; and if a third party initiates action, we will — upon request — make known to competent authorities that your actions were conducted with our authorization under this Policy. This Safe Harbour does not bind third parties and does not apply to actions outside scope or in violation of this Policy, or any activity that causes damage, service disruption, or privacy harm. You must always comply with applicable law.
  6. No NDA required. We will not require you to sign an NDA to report a vulnerability. However, anything obtained from us shall be treated with adequate discretion on your part and not disclosed to third parties, unless legally required.
  7. Recognition. Upon your request, we will acknowledge your contribution with your name/alias on our Bürkert Security Kudos Board (Hall of Fame) or respect your wish to remain anonymous. 

 

Vulnerability Handling Process

  1. Report. Reports are received through Bürkert PSIRT/CSIRT and acknowledged. If information is incomplete, additional details will be requested.
  2. Analysis. Bürkert analyzes and reproduces the reported vulnerability. If further clarification is needed, the reporter will be contacted. If the reported vulnerability cannot be reproduced, investigation may be closed with feedback.
  3. Handling. Once confirmed, remediation is planned and implemented (e.g., patches, workarounds, configuration changes). Where applicable, Bürkert may coordinate with national CSIRTs/ENISA and comply with NIS2 and CRA vulnerability handling and reporting obligations, including use of EU level vulnerability databases. The reporter will be kept informed of progress.
  4. Disclosure. After remediation, a coordinated disclosure is carried out for standard products (e.g., advisories with description, mitigations, fixes). For infrastructure‑related issues, no public disclosure will be made. The reporter will be informed of the result and credited if desired.