Vulnerability Disclosure

The Gefran Product Security Incident Response Team (PSIRT)

Technology security and reliability are a core pillar of Gefran’s offer. The PSIRT (Product Security Incident Response Team) serves as the central body responsible for managing, analyzing, and promptly resolving potential security issues or vulnerabilities across our industrial products and solutions.

Through proactive monitoring and structured report management, Gefran ensures high protection standards, safeguarding customers’ operational continuity and the resilience of field systems.

Vulnerability Management and Analysis Process

The objective of the Gefran PSIRT is to ensure prompt handling, rigorous analysis, and effective mitigation of any potential issue affecting the hardware/software infrastructure of our products or provided automation solutions.

Submission Guidelines

The sole authorized channel for receiving reports is the dedicated form accessible from this portal. The process is open to anyone who identifies an anomaly (customers, system integrators, independent researchers, or external organizations) and is handled under strict confidentiality standards.

To allow our specialists to manage the issue, the report must include:

  • Technical details of the defect: trigger mechanism, potential impact, and observed anomalous behavior.
  • System identification: specific device model or application solution part number.
  • Version information: hardware revision, firmware release, or software version in use.

The operational model of the PSIRT directly aligns with the traceability and responsiveness mandates set by European cybersecurity regulations (such as the Cyber Resilience Act – CRA), driving continuous improvements in protection standards.

Vulnerability handling relies on transparent cooperation, based on the Gefran CVD policy.

Reporting a Vulnerability

If a potential vulnerability is identified within Gefran products or solutions, reports can be submitted using the form below.

Guidelines for Reporting

Gefran’s Commitments, according to Gefran CVD Policy:

  • Traceability: Structured workflow for every received report.
  • Data Confidentiality: Information access restricted strictly to authorized personnel.
  • Identity Protection: The reporter’s identity remains confidential unless public credit is explicitly requested.

Requirements for Reporters:

  • Novelty of the vulnerability: The reported vulnerability must not have been previously published.
  • Information Quality: Submission of detailed, actionable, and reproducible technical data.
  • Valid Contacts: Provision of reliable contact details so that Gefran can reach out in case technical clarifications are needed.
  • Ethical Conduct: Adherence to responsible research practices, strictly avoiding exploitation, infrastructure attacks, or data tampering.

Gefran CVD Policy

.pdf189.54 KB