For support related inquires, please contact our support team:
Contact SupportOur policy for accepting vulnerability reports in our products
Kontron is committed to ensuring the safety and security of our customers. We hope to foster an open partnership with the security community, and we recognize that the work the community does is important in continuing to ensure safety and security for everyone.
We have developed this vulnerability policy to reflect our company values and to uphold our legal responsibility to good-faith security researchers that are providing us with their expertise.
This vulnerability disclosure policy applies to any vulnerabilities you are considering reporting to us (the “Organization”). We recommend reading this vulnerability disclosure policy fully before you report a vulnerability and always acting in compliance with it. We value those who take the time and effort to report security vulnerabilities according to this policy. However, we do not offer monetary rewards for vulnerability disclosures.
If you believe you have found a security vulnerability, please submit your report to us by email: security@kontron.com
In your report, please include details of:
If you believe you have found a new security vulnerability in a Kontron product, please submit your report to us by EMAIL to psirt@kontron.com - or via Kontron ticketing portal, if you should have an account there.
Please send information only in English.
In your report please include details of
Registered Kontron customers can check https://customersection.kontron.com/security-vulnerabilites for known security vulnerabilities, Kontron generated security advisories and an overview with impacted Kontron products and availability of fixes.
After you have submitted your report, we will respond to it within 5 working days and aim to triage your report within 10 working days. We’ll also aim to keep you informed of our progress. Priority for remediation is assessed by looking at the impact, severity and exploit complexity.
Vulnerability reports might take some time to triage or address. You are welcome to ask about the status but should avoid doing so more than once every 14 days. This allows our teams to focus on the remediation. We will notify you when the reported vulnerability is remediated, and you may be invited to confirm that the solution covers the vulnerability adequately.
Once your vulnerability has been resolved, we welcome requests to disclose your report. We’d like to unify guidance to affected users, so please do continue to coordinate public release with us.
You must:
You must NOT:
We designed this policy to be compatible with common vulnerability disclosure good practice. It does not give you permission to act in any manner that is inconsistent with the law, or which might cause the Organization or partner organizations to be in breach of any legal obligations.
Send any questions regarding this policy to security@kontron.com. We also invite you to contact us with suggestions for improving this policy.