Coordinated vulnerability disclosure policy

At celduc®, cybersecurity and product security are an integral part of our commitment to delivering reliable and secure products and solutions. We encourage customers, partners and other third parties to responsibly report potential security vulnerabilities affecting our products or services.
To report a potential security vulnerability, please follow these steps.


Reporting procedure

  • Submit the Vulnerability Report at security@celduc.com.
  • Write the Vulnerability Report in English.
  • Provide sufficient contact information, such as:
    • your email;
    • your company name + address
    • name of the person who found the vulnerability.
  • Provide information about the vulnerability:
    • date when the vulnerability has been detected;
    • details about how it has been discovered;
    • a technical description of the vulnerability.
  • Provide as much information as you can on the product or service affected by the vulnerability.
    • Product name
    • Product reference / part number
    • Hardware version, if applicable
    • Firmware/software version, if applicable
    • Serial number, if relevant
    • Description of the affected configuration
  • As well as Vulnerability information
    • Date of discovery
    • Detailed description of the vulnerability
    • Steps to reproduce the vulnerability
    • Potential impact
    • Evidence or proof of concept, if available
    • Whether you are aware of active exploitation

 

  • If you have identified specific threats related to the vulnerability, assessed the risk, or have seen the vulnerability being exploited, please provide that information together with the instructions to reproduce the vulnerability.


Internal assessment and action

  1. celduc® will acknowledge receiving your Vulnerability Report within 5 business days.
    • If the Vulnerability Report contains all the required information, celduc® will contact you and provide a follow-up number;
    • If the Vulnerability Report is not complete (more information is needed), celduc® will request you the missing information. In case the reporter does not respond within 30 days, the report will be automatically considered resolved.
  2. celduc® will start an internal Vulnerability Management Process to manage the reported vulnerability:
    • Vulnerability Identification;
    • Vulnerability Triage;
    • Vulnerability Assessment;
    • Vulnerability Addressing.
  3. celduc® will monitor the status of the Vulnerability Management Process, and will keep you updated until the resolution of the security issue.
  4. celduc® will use existing customer notification processes to manage the release of patches or security fixes, which may include without limitation and at celduc®’s sole discretion, direct customer notification or public release of an advisory notification on our website.
  5. If the vulnerability is actually in a third party component or service which is part of our product/service, Celduc® will notify the Vulnerability Report to that third party and advise you of that notification. To that end, please inform us in your email whether it is permissible in such cases to provide your contact information to the third party.


Personal data

Any personal data provided as part of a vulnerability report will be processed by celduc® in accordance with our Privacy Policy.


Contact

For security vulnerability reports: security@celduc.com

For general product or technical support enquiries, please use our regular contact channels.