Report a security vulnerability

Found a vulnerability in one of our products? Let us know.

The security of our modules, DEVKITs and board support packages does not end at delivery. Reports from the security community, from customers and from partners are an essential part of how we manage vulnerabilities. We handle every report in a structured way and keep you informed about its status.

Please send security vulnerability reports to:  scrtybytstwrkch

What your report should contain

The more complete your information, the faster we can reproduce and assess the issue:

  • Product and version: module designation, revision, BSP or image version, kernel and U-Boot version
  • Description of the vulnerability: nature of the problem and affected component
  • Reproduction: clear steps, ideally with proof of concept, logs or configuration
  • Impact: what an attacker can achieve, under which conditions, with what level of access
  • Environment: carrier board, wiring, network connection, non-standard configuration

Safe harbour

We will not take legal action against anyone who investigates a vulnerability in good faith and reports it to us. This assumes that you test only on your own devices or with permission, do not exfiltrate, alter or delete third-party data, do not affect the availability of our products and services, and do not access more than is necessary to demonstrate the issue.

We do not run a bug bounty programme and do not pay rewards.

Datenschutzhinweis

Diese Webseite nutzt externe Komponenten, wie z.B. Google Analytics, Google Maps, und Youtube, welche dazu genutzt werden können, Daten über Ihr Verhalten zu sammeln. Datenschutzinformationen

Notwendige Cookies werden immer geladen