+49 (0) 2335 68277-0

Security

Reporting Security Vulnerabilities

Thank you for your interest in the security of our products.

SOREL GmbH welcomes reports of potential security vulnerabilities in its products and online services. If you have discovered a vulnerability, please report it to us in a responsible manner. In doing so, you will help us to continuously improve the security of our products.

Contact

Please send your report to:

cybersecurity[@]sorel.de

If your report contains confidential information, please let us know. If necessary, we will provide you with a suitable encrypted communication channel.

Responsible disclosure

We ask that you report security vulnerabilities exclusively to SOREL in the first instance, allow us sufficient time to assess and rectify the issue, and refrain from publicly disclosing any information about unpatched vulnerabilities.

Undesirable Activities

Please do not carry out any actions that compromise the availability of our systems, unnecessarily access, alter or delete third parties’ personal data, involve social engineering or phishing, involve physical attacks on our facilities, or result in disruption to customer or production systems.

Note

This reporting channel is intended solely for reporting security vulnerabilities. For technical support, product enquiries or general enquiries, please use the standard contact options on our contact page.

Thank you for your support in improving the security of our products.

What information should a report contain?

To enable us to review your report as quickly as possible, please provide the following details:

  • Product name and firmware version
  • Description of the vulnerability
  • Steps to reproduce the issue
  • Possible consequences
  • Screenshots, log files or proof-of-concept, where applicable

How we handle your report

Upon receipt of your report, we will investigate the reported vulnerability, contact you if we have any queries, and, where possible, keep you informed of the progress of the investigation.

Please note that the processing time depends on the scope and complexity of the report.

Please provide the following information: product name, software/firmware version, description of the vulnerability