JavaScript is required

Reporting vulnerabilities

Cyber security of our products is very important to us. Should you nevertheless discover any vulnerability, please do not hesitate to contact us. We will address every reported vulnerability promptly and thoroughly in accordance with the Cyber Resilience Act (Regulation (EU) 2024/2847).

Before reporting a vulnerability to us, please check the following:

  1. Is one of our products (including the software components used in them) affected by the vulnerability?
  2. Have you complied with our CVD guideline?

If you have answered both questions with Yes, please send your report to our central security e-mail address: report-vulnerabilities@resol.de

Security researchers can additionally report a vulnerability via the central EU reporting platform (Single Reporting Platform) of ENISA:

https://www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp

Template for your report

A detailed report helps us identify, address and resolve the vulnerability more quickly. We therefore ask you adhere to the following structure as closely as possible:

  1. Designation of the vulnerability (e.g. SQL injection, XSS, etc.)
    • If possible, please use a CWE number for this purpose
  2. Short description of the vulnerability
  3. Affected product: Product type and serial number according to the type label
  4. Comprehensive description of the vulnerability (including technical details)
  5. A proof of concept, if available (e.g. code snippets or screenshot)
  6. Possible countermeasures, if you are already aware of any solutions
  7. Your contact details (name/alias and e-mail address for possible enquiries)

The CWE (Common Weakness Enumeration) number describes the type of vulnerability (the cause). CWE is a formalised dictionary of software and hardware vulnerabilities maintained by the MITRE Corporation.

CVD Policy (Coordinated Vulnerability Disclosure)

Our promise to:

  • treat every vulnerability report confidentially, not pass on personal data to third parties without your express consent.
  • confirm receipt of a vulnerability report. Afterwards, you will be informed as soon as possible of the planned timeframe for rectifying the vulnerability. We are your contact person for the trustful exchange during the entire process.
  • publish all vulnerabilities known to us on our website. If you wish, we will publish your name or alias along with the vulnerability reported. This is how we thank you.
  • not to take any legal action against you as long as you have complied with the guideline and the principles. This does not apply if recognisable criminal intentions were or are being pursued.

We expect that

  • you provide valid contact details, so that we can get in touch with you in case of enquiries. If you wish to stay anonymous, you can use an alias.
  • your vulnerability report does not consist of results from automated tools or scans without explanatory documentation, nor of vulnerabilities that have already been fixed. These do not constitute valid vulnerability reports.
  • the vulnerability discovered was not exploited in an abusive manner. This means, for example, that data was downloaded, altered or deleted, or that your own programme code was uploaded or stored on the systems.
  • no attacks (such as social engineering (e.g. phishing), spam, (distributed) DoS or ‘brute force’ attacks, etc.) were carried out against our IT systems, our or our customers’ infrastructure or systems. This also includes the manipulation or compromise of customer systems.
  • a vulnerable system has not been accessed multiple times.
  • no information regarding the vulnerability has been disclosed to third parties without our explicit authorisation.
  • no tools for exploiting vulnerabilities, e.g. for sale or for free on darknet markets, have been offered, which could be used by third parties to commit criminal offences.