Our commitment
The security of our products is a top priority at HEIDENHAIN. We have a systematic process for handling reported security vulnerabilities regarding our products, solutions, and IT infrastructure, and collaborate closely with anyone who reports vulnerabilities. Complying with, continuously monitoring, and implementing regulatory requirements, such as the Cyber Resilience Act (CRA), are an integral part of our cyber security management process.
The following guidelines explain how vulnerabilities can be reported and how we handle them.
Applicability
These guidelines apply to all products offered by HEIDENHAIN, regardless of whether they are subject to servicing agreements and regardless of their status within the product life cycle.
We welcome reports from any source: researchers, trade associations, CERTs, partners, or third parties. We do not require a confidentiality agreement as a condition for accepting reports.
If your report is about our digital infrastructure (e.g., our website or active services), please send us an email to security@heidenhain.com.
Information for security researchers
HEIDENHAIN will not take legal action against reporting individuals if the following conditions are met:
- No harm to individuals
- Testing only to the extent necessary to verify a vulnerability
- Testing on productive systems only with explicit authorization
- No impairment of availability (no DoS attacks), no social engineering, and no access to physical infrastructure
- Access only to the data required for demonstration purposes; no modification, deletion, or exfiltration of data
- Protection of the security and privacy of others
- Compliance with applicable laws
- Willingness to coordinate disclosure (no public disclosure before the expiry of a mutually agreed period)
We value your reports and their ability to help us quickly remediate problems.
Guidelines for security researchers
- Notify us as early as possible about actual or potential security problems.
- Use exploits only to the extent necessary to verify the vulnerability.
- Give us sufficient time to remediate the problem. We will publish significant and confirmed vulnerabilities through CERT@VDE.
- Immediate public disclosure would create a “zero-day” situation and would expose our customers' systems, including critical infrastructure, to unnecessary risks. We therefore strongly request coordinated disclosure.
Reporting a vulnerability
- To send a detailed vulnerability report, along with any related files and confirming evidence, please use our cyber security contact form.
- Email: product-security@heidenhain.com (The email addresses stated in our security.txt are intended solely for initial contact and are not to be used for sending sensitive or detailed information regarding vulnerabilities.)
- Reporting through CERT@VDE: https://www.certvde.com/en/service/report-a-vulnerability/
What the report should contain
If possible, please provide the following information:
- The affected product or software (including ID number and software or firmware version)
- Description of the vulnerability, where it was found, and its potential effects
- Any reproducible steps (PoC, scripts, screenshots, network data)
- Whether or not the vulnerability is already public knowledge
- Any relevant documents (CVE, notifications, release notes)
- Preferably a description in English
How we process reports
- Report received: We provide confirmation that the report was received.
- Assessment: We examine and reproduce the vulnerability, requesting more information if needed.
- Handling: We coordinate remediation and keep you informed.
- Public disclosure: As soon as a solution is available or has been published (whichever occurs first), we will publish a security advisory. CVE entries will be created in coordination with CERT@VDE and published in accordance with the CSAF.
What our security advisories contain
![[Translate to English:] PSIRT [Translate to English:] PSIRT](/fileadmin/Bilder/Platzhalterbilder/CRA.jpg)