top of page
AE-Logo2020_4c-RGB.png

Reporting Security Vulnerabilities (Coordinated Vulnerability Disclosure)

The security of our products is a high priority for Advanced Engineering. If you have discovered a security vulnerability in one of our products, we ask you to report it to us responsibly. We take every report seriously.

a) SCOPE

This policy applies to all Advanced Engineering products, in particular:
- Industrial automation machines incl. control technology
- PLC software
- Comandra (SCADA/HMI)

For vulnerabilities in third-party products (e.g. operating systems, controller
components from other manufacturers), please contact the respective manufacturer. We
are happy to forward your report if the attribution is unclear.

b) How to report a vulnerability

Send your report to: security@advanced-engineering.at

Where possible, please describe:
- Affected product and version
- Type of vulnerability and potential impact
- Steps to reproduce (proof of concept, screenshots, logs)
- Your contact details for follow-up questions (anonymous reports are also accepted)

c) What you can expect from us

- Acknowledgement of receipt within 5 business days.
- We will assess the report and keep you informed about the status.
- We will inform you as soon as a fix is available.
- On request, we will credit you in the related security advisory (or refrain from doing so).

d) Coordinated disclosure

We ask you to treat information about the vulnerability confidentially until a fix is
available. As a guideline, we aim for remediation within 90 days; for complex cases
(e.g. plants in the field) we will agree a realistic timeline with you.

e) Legal (safe harbor)

If you adhere to this policy when discovering and reporting – in particular: do not
access, modify or delete third-party data, do not impair the operation of plants, and
do not exploit the vulnerability beyond what is necessary to demonstrate it – we will
not take legal action against you on account of your report.

f) ADDITIONAL NOTES

- We currently do not operate a bug bounty programme; no rewards are paid.
- Out of scope: spam/phishing reports, reports about missing best practices without a
concrete security risk (e.g. missing HTTP headers on the corporate website), and
denial-of-service testing against production systems.

CYBERSECURITY DISCLOSURE
 

bottom of page