Version 1.0
Effective date: 11 September 2026
Last updated: 11 September 2026
← Product Security (PSIRT) overview
COORDINATED VULNERABILITY DISCLOSURE (CVD)
The Coordinated Vulnerability Disclosure (CVD) Policy explains how security researchers, customers, authorities and other parties can report suspected or confirmed vulnerabilities and security incidents to Wieland Electric. It defines the scope of the policy, the available reporting channels and how we assess, coordinate and communicate reported issues.
To report a vulnerability, please use our vulnerability reporting form.
DOWNLOAD THE CVD POLICY
A.1 Introduction
Wieland Electric GmbH takes reports of potential security vulnerabilities and security incidents seriously. This CVD Policy describes how security researchers, customers, authorities and other reporting parties can report suspected or exploited vulnerabilities and security incidents to Wieland Electric GmbH securely and in a coordinated manner, and how Wieland Electric GmbH handles such reports.
This Policy applies to all products with digital elements and related digital services placed on the market by Wieland Electric, as well as the infrastructure operated for them by Wieland Electric GmbH.
The CVD Policy and the central reporting page are available in German and English. Incoming reports are handled in German and English.
A.2 How to Report a Vulnerability or Security Incident
Please report suspected or exploited vulnerabilities and security incidents through one of the following channels:
- Web form (preferred): Report a vulnerability
- PSIRT mailbox (psirt@wieland-electric.com)
- CSIRT mailbox (csirt@wieland-electric.com)
A.3 Information That Helps Us
Reports can be processed more quickly when they contain as much of the following information as possible:
- affected product, service or infrastructure; article number; software or firmware version; hardware version; serial number; or affected URL;
- description of the vulnerability or information security incident;
- steps to reproduce, logs, screenshots, software tools used and relevant technical conditions;
- assessment of severity, exploitability (including any exploitation already observed), affected configurations and impact on security objectives (confidentiality, integrity, availability and functional safety);
- any time dependencies, such as a planned publication or conference presentation;
- contact details, such as an email address or telephone number, for follow-up questions unless the report is submitted anonymously.
Reporting parties are asked to protect personal, confidential and business-critical information when preparing a report. Only information required to reproduce, assess and address the issue should be submitted for the purpose of analysing the report.
In particular, when providing reproduction steps, logs, screen recordings, memory dumps or other supporting evidence, personal data and confidential information should, wherever possible, be removed, anonymised or redacted. This includes, for example, names, usernames, email addresses, telephone numbers, IP addresses, customer and order data, authentication information, credentials, or other information that could identify individuals or disclose confidential business processes.
Where transmitting specific personal or confidential information is unavoidable for analysing the vulnerability, reporting parties should limit it to the minimum necessary and clearly identify it as such in their report.
Wieland Electric GmbH reserves the right to delete, anonymise or exclude from further processing any submitted information that is not required to process the report.
As a general rule, we consider a vulnerability valid if it affects a product, component or service distributed by Wieland Electric GmbH, or the IT infrastructure operated for it. Reports concerning vulnerabilities that are not publicly known are prioritised. Results from automated vulnerability scans without adequate supporting documentation can only be assessed to a limited extent, but will be reviewed to the best of our ability.
As a general rule, we consider an information security incident valid if it is connected with a product, component or service distributed by Wieland Electric GmbH, or the IT infrastructure operated for it. This connection may arise, for example, because such a product, component, service or infrastructure caused or was affected by the incident.
A.4 Expected Conduct of Reporting Parties
We ask reporting parties to act in good faith and responsibly. In particular, we expect them to:
- limit testing to the minimum necessary to confirm the vulnerability or security incident;
- not exploit the vulnerability beyond what is necessary to demonstrate it, establish persistence, move laterally, or manipulate data or systems;
- not carry out denial-of-service, spam, brute-force, social-engineering or phishing attacks;
- not access, store or disclose personal or confidential data;
- not publicly disclose technical details before coordinating with Wieland Electric GmbH where doing so could put users at risk;
- not engage in extortion or make reporting conditional on payment or other consideration;
- communicate respectfully, without discrimination, threats or insults.
Even where conduct deviates from these expectations, Wieland Electric GmbH will review the report to the extent possible and necessary to protect its customers.
A.5 Our Commitments to Reporting Parties
- We treat incoming reports as confidential to the extent permitted by law, unless disclosure is required for remediation, user notification or statutory reporting.
- We do not disclose a reporting party's personal data to third parties without their express consent unless required by law.
- We do not require reporting parties to enter into a non-disclosure agreement (NDA) as a condition of processing a report.
- Throughout the CVD process, we are available as a trusted point of contact and respond to status enquiries.
Where reporting parties comply with this Policy and its principles, Wieland Electric GmbH, at its own discretion and to the extent permitted by law, will neither file a criminal complaint nor pursue civil claims in connection with a good-faith report. This does not apply in cases of evident criminal intent, extortion, intentional harm, unauthorised use of third-party data, significant disruption, or other unlawful acts outside the scope of this Policy.
A.6 Anonymous Reports
Reports may be submitted anonymously through the web form. Please note that anonymous reports can only be processed to a limited extent if follow-up questions or additional technical information are required. In complex cases, the inability to contact the reporting party may prevent the report from being fully validated or verified.
A.7 Response Times
The following guaranteed response times apply to non-anonymous reports:
| Stage | Time frame | Details |
| Acknowledgement of receipt | Immediately upon receipt of the report | Automatically generated acknowledgement of receipt |
| Initial response | Within 5 working days of receipt | Acceptance or rejection of the report; technical follow-up questions |
| Detailed response | Within 10 working days of receipt | Findings from the assessment of the report, for example concerning exploitability and reproduction |
Statutory reporting deadlines to authorities and ENISA for actively exploited vulnerabilities or severe security incidents remain unaffected.
A.8 Remediation, User Information and Coordinated Disclosure
Wieland Electric GmbH assesses and handles reports using a risk-based approach:
- Report validation. Wieland Electric GmbH determines whether a reported security incident is connected with, or a reported vulnerability affects, a product or service placed on the market by Wieland Electric GmbH, or infrastructure operated for it. This includes identifying the affected products, services and infrastructure and their versions.
- Remediation. Wieland Electric GmbH coordinates remediation or risk mitigation and informs affected customers where necessary. During the applicable support period, security updates are generally provided at no additional cost where required by law and separately from feature updates where technically possible.
- Disclosure. Wieland Electric GmbH generally discloses validated and exploitable vulnerabilities publicly within 90 working days, unless the vulnerability was remediated before the affected product was placed on the market. If remediation or risk mitigation requires more time for substantiated reasons, disclosure may be extended once by up to a further 90 working days in close coordination with ENISA. Any further extension will be made only in coordination with ENISA. The level of technical detail and timing of publication are selected to protect customers and avoid unnecessary exploitation risks. Affected customers may be informed directly and on a risk-based basis before general public disclosure. Once a remediation is available, Security Advisories are published, including the affected products, severity, impact and actions for customers. Wieland Electric GmbH aims to provide machine-readable formats such as CSAF.
A.9 Data Protection
Wieland Electric GmbH processes reporting parties' personal data solely for handling vulnerability reports, communicating during the CVD process, complying with legal obligations and, where applicable, publishing an acknowledgement with their express consent. Please avoid transmitting third parties' personal data. Further details are available in the Wieland Electric GmbH Data Privacy Statement.
A.10 Acknowledgement
At the reporting party's request, and following completion of a valid CVD process, Wieland Electric GmbH may name them on a dedicated acknowledgements page using their name or alias and include an appropriate reference. Publication takes place only with the reporting party's express consent. This Policy does not create any entitlement to financial compensation or participation in a bug bounty programme. See Security Acknowledgements.
A.11 Conclusion of the CVD Process
A CVD process is considered complete when one of the following applies:
- the report is unfounded or does not concern a product, component or service of Wieland Electric GmbH, or infrastructure operated for it;
- a vulnerability in a product, component or infrastructure operated for service provision has been remediated, for example by a patch, update, configuration change or other measure, and, where required, disclosed;
- the reporting party has not responded to follow-up questions for at least 30 days and the report can therefore only be processed to a limited extent or cannot be processed further;
Reporting parties who have not submitted anonymously will be informed of the conclusion without undue delay.
A.12 Other Provisions
All periods stated in working days are calculated on the basis of the working days applicable in the Free State of Bavaria. For the purposes of this Policy, working days are Monday to Friday, excluding public holidays in the Free State of Bavaria. Saturdays, Sundays and public holidays in Bavaria are not working days.
To report a vulnerability, please use our vulnerability reporting form.