Vulnerability Disclosure Policy

Introduction

Since security is of critical importance to us and to our customers, we at SandenVendo Europe S.p.A. are committed to ensuring the safety and security of our products and services. SandenVendo Europe S.p.A. supports coordinated vulnerability disclosure and encourages responsible vulnerability testing; we take any reports of potential security vulnerabilities seriously.

To report a potential security vulnerability, please follow the steps described in the “Reporting procedure” section.

How to Report a Vulnerability

  • Submit the Vulnerability Report at security@sandenvendo.it.
  • Use our PGP public key (https://my.sandenvendo.it/cra-security/pgp-key.asc) to encrypt any email submissions.
  • Write the Vulnerability Report in English.
  • Provide sufficient contact information, such as:
    • your email;
    • name of the person who found the vulnerability.
  • Provide information about the vulnerability:
    • date when the vulnerability has been detected;
    • details about how it has been discovered;
    • a technical description of the vulnerability.
    It is important to indicate whether there is any suspect or confirmed evidence that the vulnerability has been actively exploited.
  • Provide as much information as you can on the product or service affected by the vulnerability, like:
    • version number (hardware and software);
    • configuration of the setup used.
  • If you wrote specific proof-of-concept or exploit code, please provide a copy. Please ensure all submitted code is clearly marked as such and is encrypted with our PGP key.
  • If you have identified specific threats related to the vulnerability, assessed the risk, or have seen the vulnerability being exploited, please provide that information.

Evaluation and Management Process

  • SandenVendo Europe S.p.A. will acknowledge receiving your Vulnerability Report within 5 business days.
  • If the Vulnerability Report contains all the required information, SandenVendo Europe S.p.A. will provide a unique tracking number and a contact person.
  • If the Vulnerability Report is not complete (more information is needed), SandenVendo Europe S.p.A. will request the missing information, and no more action will be taken.
  • SandenVendo Europe S.p.A. will start an internal Vulnerability Management Process to manage the reported vulnerability:
    • Vulnerability Receipt;
    • Vulnerability Triage;
    • Vulnerability Verification;
    • Vulnerability Remediation.
  • SandenVendo Europe S.p.A. will monitor the status of the Vulnerability Management Process, and you will receive a communication at the end of each stage.
  • SandenVendo Europe S.p.A. will use existing customer notification processes to manage the release of patches or security fixes, which may include, without limitation and at SandenVendo Europe S.p.A.’s sole discretion, direct customer notification or public release of an advisory notification on our website.
  • If the vulnerability is actually in a third-party component or service which is part of our product/service, SandenVendo Europe S.p.A. will notify the Vulnerability Report to that third party and advise you of that notification. To that end, please inform us in your email whether it is permissible in such cases to provide your contact information to the third party.

Notes

If you share any information with SandenVendo Europe S.p.A. in the context of responsible disclosure, you are agreeing that the information you submit will be considered as non-proprietary and non-confidential.

SandenVendo Europe S.p.A. is allowed to use shared information, or part of it, without any restriction. You agree that submitting information does not create any rights for you or any obligation for SandenVendo Europe S.p.A.

Personal data is processed by SandenVendo Europe S.p.A. based on the privacy policy.

Source: 'Vulnerability Disclosure Policy - Template' by Security Pattern

Security Contact