
Product Security & Vulnerability Reporting
Report a security vulnerability
HOERBIGER is committed to maintaining the security, reliability, and resilience of its products and digital solutions.
If you have identified a potential security vulnerability affecting a HOERBIGER product, software application, digital service, or connected system, please report it using the contact details below. We appreciate responsible disclosures and will investigate all legitimate reports.
Report a vulnerability: ProductSecurity@hoerbiger.com
Report a vulnerability
Contact Information
Email: ProductSecurity@hoerbiger.com
Information to include
To help us evaluate your report efficiently, please provide:
- Product name and version
- A detailed description of the vulnerability
- Potential business or security impact
- Steps required to reproduce the issue
- Screenshots, logs, and supporting evidence
- Your name, organization, and contact details
What should be reported?
Examples include:
- Security vulnerabilities in HOERBIGER products
- Software or firmware vulnerabilities
- Authentication or authorization weaknesses
- Data exposure risks
- Remote access vulnerabilities
- Web application security issues
- Cybersecurity incidents affecting HOERBIGER digital products and services
- Indicators of Compromise (IoC), or Attack (IoA)
Not covered by this process
Please use other contact channels for:
- Product support requests
- Service or maintenance inquiries
- Warranty claims
- Sales inquiries
- General customer feedback
Responsible disclosure policy
HOERBIGER supports responsible vulnerability disclosure and values collaboration with the cybersecurity community.
We ask security researchers and reporters to:
- Act in good faith
- Avoid disruption of customer or business operations
- Avoid accessing, modifying, or deleting data that does not belong to you
- Refrain from conducting denial-of-service or availability testing
- Give HOERBIGER reasonable time to investigate and remediate validated vulnerabilities before public disclosure
- Comply with all applicable laws and regulations
Our commitment
Upon receiving a report, HOERBIGER will:
- Acknowledge receipt of the report
- Review and validate the findings
- Assess the potential impact and severity
- Coordinate remediation activities where required
- Communicate with the reporter when additional information is needed
- Work to resolve confirmed vulnerabilities in an appropriate timeframe
Please note that response and remediation times may vary depending on the complexity and severity of the issue.
Legal safe harbor
HOERBIGER supports security research conducted in good faith.
HOERBIGER will not initiate legal action against individuals who:
- Follow this disclosure policy
- Act in good faith
- Avoid unauthorized access to data
- Avoid service disruption or damage
- Do not exploit vulnerabilities beyond what is necessary for validation and reporting
This statement does not apply to activities that violate applicable laws, regulations, or contractual obligations.
Privacy notice
The information submitted through this reporting channel may contain personal data.
HOERBIGER will process submitted information solely for the purposes of:
- Investigating reported vulnerabilities
- Assessing cybersecurity risks
- Coordinating remediation activities
- Meeting legal and regulatory obligations
For more information, please refer to our Privacy Notice.
Link: Privacy Notice
Product security governance
HOERBIGER maintains processes for:
- Vulnerability management
- Security incident response
- Security risk assessment
- Product security lifecycle management
- Security update and remediation management
These processes support our commitment to secure products and compliance with applicable cybersecurity regulations.
Regulatory compliance
HOERBIGER operates product security processes designed to support applicable cybersecurity and product security requirements, including the EU Cyber Resilience Act where relevant.
Reports submitted through this channel will be assessed in accordance with HOERBIGER's internal product security procedures and applicable legal requirements.
Frequently asked questions
Will I receive a response?
HOERBIGER will acknowledge legitimate vulnerability reports and may contact you if additional information is required.
Can I disclose a vulnerability publicly?
We request coordinated disclosure and ask that you allow sufficient time for investigation and remediation before public disclosure.
Does HOERBIGER offer a bug bounty program?
HOERBIGER currently does not operate a bug bounty program unless explicitly stated otherwise.
Can customers report cybersecurity incidents?
Yes. Customers may use this channel to report cybersecurity incidents affecting HOERBIGER products and services.
Related information
Contact: ProductSecurity@hoerbiger.com