Vulnerability Reporting
In accordance with the Cyber Resilience Act 2024/2847, Article 14(4)
1. Product Security Incident Response Team (PSIRT)
ACR Brändli + Vögeli AG is committed to maintaining the security of its products and services.
We welcome reports from customers, business partners, distributors, system integrators and other third parties who identify potential security vulnerabilities in products marketed under the brand XZENT.
2. Report a Vulnerability
If you believe you have discovered a cybersecurity vulnerability affecting one of our products, please report it to our Product Security Incident Response Team (PSIRT).
E-Mail: security@xzent.com
Do not use this contact for:
- Product support requests
- Warranty claims
- Sales inquiries
- General technical support
Note: Inquiries to any of the above off-topics subjects will be ignored and remain unanswered.
3. Information Required
The report of a suspected vulnerability shall include:
- Brand
- Model
- Hardware revision (if known)
- Software / firmware version
- Detailed vulnerability description
- Reproduction steps
- Proof-of-concept material
- Potential impact
- Your contact information
4. Coordinated Vulnerability Disclosure Policy
ACR supports Coordinated Vulnerability Disclosure (CVD). Yet we request firmly, that vulnerabilities are reported confidentially and not disclosed publicly until remediation activities have been completed or disclosure has been coordinated with ACR.
4.1 Safe Harbor Clause
ACR will not initiate legal action against researchers who:
ACR will not take legal action against security researchers who:
- act in good faith,
- avoid data breaches,
- do not exploit vulnerabilities beyond what is necessary to demonstrate their existence,
- and comply with this disclosure policy.
Therefore, activities conducted in accordance with this safe-harbor policy are considered to be authorized.
5. Response Commitments
We aim to:
- Acknowledge receipt within 7 calendar days
- Perform an initial assessment within 30 calendar days
- Remediation priorities are determined based on risk, impact and severity
Note: The deadlines listed are targets and do not constitute a legal entitlement.
6. Vulnerability Severity Handling
Reported vulnerabilities are evaluated using CVSS and internal risk assessment criteria.
Severity categories:
- Critical
- High
- Medium
- Low
7. Security-Relevant Software Updates
Security-relevant software and firmware updates are provided on the respective product- or brand-specific support pages. Please check the relevant update page for your product regularly.
8. Product Security Update Policy
Security updates are provided for supported products during the declared support period. Support periods are communicated in product documentation and may vary strongly depending on product type and sales quantity.
