Vulnerability Disclosure Policy
- Purpose
- Scope
- Roles and Responsibilities
- Contact points for vulnerability reports
- Expectations to security researchers (Safe Harbour)
- Our commitments to reporting entities
- What constitutes a valid vulnerability report
- Code of conduct for reporting entities
- Good communication practices
- Documentation requirements for reporters
- Reaction process
- Completion of the CVD process
- Statutory reporting obligations (Cyber Resilience Act)
- Confidentiality & data management
- Review and Updates of this policy
- Terms and abbreviations
Purpose
Gigaset Technologies GmbH (hereinafter "Gigaset") is committed to ensuring the security of its products, services, and systems. This Vulnerability Disclosure Policy (VDP) also known as Coordinated Vulnerability Disclosure (CVD) policy defines the process by which external security researchers, customers, and members of the public may report potential security vulnerabilities to Gigaset.
This policy is designed in accordance with prEN 40000-1-3 which establishes requirements and recommendations for manufacturers of products with digital elements on the disclosure of potential vulnerabilities in their products during the product's life cycle / support period.
Our goal is to ensure a transparent, consistent, and responsible approach to handling security vulnerabilities in order to protect our customers, users, and systems.
This policy applies to vulnerabilities that may negatively impact:
- confidentiality
- integrity
- availability
- authenticity
- non‑repudiation
- reliability
of all Gigaset products with digital elements, including software, firmware and device components.
Gigaset has formalized a process for handling reported security vulnerabilities in its product portfolio.
We welcome good-faith security research and appreciate contributions that help improve our security posture.
Our principles of responsible disclosure
Gigaset is committed to Coordinated Vulnerability Disclosure (CVD) in accordance with the basic principles:
- Protecting users from active threats
- Timely provision of security updates and information
- Transparency and documentation of all step
- Responsible collaboration with researchers, customers and partners
Scope
In-Scope Assets
The following systems, products, and services are within the scope of this policy:
- all Gigaset products with digital elements, including software, firmware and device components
Out-of-Scope
The following are explicitly excluded from this policy:
- Third-party products, services, or infrastructure not owned or operated by Gigaset
- Social engineering, phishing, or physical security attacks
- Denial of Service (DoS) or Distributed Denial of Service (DDoS) attacks
- Vulnerabilities in end-of-life systems or products no longer supported
- Issues already known to Gigaset or previously reported
Roles and Responsibilities
The following roles are defined within this policy:
Product Security Incident Response Team (PSIRT)
The designated internal team responsible for managing vulnerability disclosures is the Product Security Team (PST). This team is responsible for:
- Receiving and acknowledging vulnerability reports
- Triaging, investigating, and prioritising reported vulnerabilities
- Coordinating remediation efforts with relevant internal teams
- Communicating with the reporter throughout the process
- Publishing advisories or notifications where appropriate
Reporter
Any individual or organisation that identifies and submits a potential vulnerability. Reporters are expected to:
- Act in good faith and adhere to the terms of this policy
- Avoid unauthorised access to, or modification of, data
- Not disclose the vulnerability publicly before Gigaset has had a reasonable opportunity to remediate it
- Provide sufficient detail to allow Gigaset to reproduce and validate the issue
Contact points for vulnerability reports
Vulnerability reports should be submitted through the following channels:
- Web form: Security Report | Gigaset
- E‑Mail: productsecurity@gigaset.com
- Customer Service
- Private customers: Service-Portal | Gigaset
- Business customers: Pro Business Service-Portal | Gigaset
The contact points are intended solely for reporting security vulnerabilities.
Anonymous reporting
- An easy-to-find anonymous reporting option is available (web form).
- Anonymous reports may limit our ability to investigate or act on the findings.
- Lack of response to technical questions may result in partial or no processing of the report.
Expectations to security researchers (Safe Harbour)
Gigaset respects responsible researchers and expect:
- No exploitation beyond what is necessary for verification
- No publication without prior coordination
- No access to personal data (if avoidable)
In return, Gigaset guarantees:
- No legal action against bona fide, responsible reports
- Recognition in advisories (upon request)
Our commitments to reporting entities
Gigaset commits to the following principles:
Confidentiality and data protection
- All vulnerability reports will be treated confidentially to the extent permitted by law.
- Gigaset will not share personal data of the reporting entity without explicit consent.
Timely responses
- Initial human response within 5 business days
- Detailed follow-up within 10 business days
This follow‑up will include:
- confirmation or rejection of the vulnerability, or
- meaningful questions for clarification, or
- an explanation for delays and a renewed commitment to provide updates at least every 10 business days.
No legal action for good-faith research
Gigaset will not pursue legal action against individuals who:
- act in good faith,
- comply with this policy,
- avoid causing harm,
- and do not demonstrate malicious intent.
Communication and recognition
- Gigaset provides open communication throughout the entire process.
- Upon request, valid reporters may be acknowledged on our Hall of Fame after completion of the CVD process.
- No Non-Disclosure Agreement (NDA) is required to submit a report.
What constitutes a valid vulnerability report
A submission should meet these criteria:
- The vulnerability affects a product, service, or infrastructure of Gigaset.
- The information is not publicly known at the time of reporting.
- Automated scan results alone may be insufficient unless accompanied by supporting evidence.
We publish a detailed vulnerability reporting guideline on our security page.
Code of conduct for reporting entities
To ensure a safe and constructive process, we expect reporting entities to:
- Refrain from exploiting the vulnerability beyond what is necessary for proof-of-concept.
- Avoid actions such as social engineering, spam, denial-of-service attacks, brute force, or any activity that could harm systems or users.
- Avoid manipulating or compromising third-party systems or data.
- Not sell or distribute exploit tools.
- Use respectful communication without discrimination or insults.
Possible consequences of non‑compliance:
- No eligibility for rewards or bug bounty payments.
- No listing on the Hall of Fame.
Regardless of compliance, we will still handle the report to the best extent possible.
Good communication practices
Gigaset encourages:
- Clear, detailed reporting including steps to reproduce the issue.
- At least one valid contact method (unless reporting anonymously).
- Follow-up questions from the reporting entity regarding status.
Gigaset guarantees:
- All reports are reviewed and processed.
- No single analyst can close a case without additional review.
- Reports about already fixed vulnerabilities are still welcomed and evaluated.
Documentation requirements for reporters
To enable efficient triage, reporters should provide the following information where possible:
- Affected product(s), version(s), and/or URL(s)
- Description of the vulnerability and its potential impact
- Step-by-step instructions, including tools, to reproduce the vulnerability
- Supporting evidence such as screenshots, network captures, or PoC code
- Suggested CVSS score or severity assessment (optional)
- Contact details for follow-up communication
Reaction process
Gigaset follows the vulnerability handling process defined in prEN 40000-1-3, consisting of the following phases:
Receipt & confirmation
Upon the receipt of the report of a potential vulnerability, the Organization will acknowledge receipt of the report within 5 business days of submission. The acknowledgement will include a unique tracking number.
Analysis & evaluation
Upon acknowledgement, the security team will assess the report within 10 business days. During this phase, Gigaset will:
- Validate the vulnerability and attempt to reproduce it
- Assess severity using a recognised scoring system (CVSS v3.0)
- Determine affected product(s) and version(s)
- Assign an internal priority and remediation owner
If the report initially submitted does not contain sufficient information to reproduce the vulnerability, the security team will contact the reporter to request additional details.
Correction & verification
Gigaset will develop and test a remediation or mitigation for validated vulnerabilities. Remediation timelines are guided by severity during the support period:
| Target Timeline |
|---|
| Target fix within 90 calendar days |
| Exceptional cases: Extended timelines communicated to reporter in advance |
One-time extension of another 90 days is possible with justification, in coordination with the national CSIRT.
Coordinated disclosure
Gigaset supports coordinated public disclosure. Prior to any public disclosure, both parties should agree on:
- The disclosure date
- The content of any public advisory or statement
- Any embargo period required to protect users
Gigaset reserves the right to disclose vulnerability information without the reporter's involvement where it is necessary to protect users or comply with legal obligations.
Once remediation is complete, Gigaset will:
- Notify the reporter that the vulnerability has been resolved
- Publish a security advisory or release note as appropriate
- Credit the reporter (if consent is provided) in any public advisory
Gigaset targets a coordinated disclosure window of no more than 90 calendar days from the date of acknowledgement. If this window cannot be met, the reporter will be notified and a revised date agreed upon.
Content of security advisories
Security advisories contain at least:
- Description of the vulnerability
- Severity / CVSS
- Affected products & versions
- Measures, updates, workarounds
- Acknowledgement to the reporter (optional)
- Publication Date / History of changes
Permission for Use of security advisories
Gigaset grants third parties the right to use, redistribute, and modify the Gigaset Security Advisories published on Security Advisories. This includes permission for commercial use.
Third parties are allowed to modify the text of the Gigaset Security Advisories and redistribute the modified content. However, the following conditions must be met:
- Any modifications must be technically correct.
- Modifications must be in line with Gigaset's recommendations given in the respective Security Advisory.
- Regardless of any modifications made, all redistributed versions of the Security Advisories must include a link to the original text of Gigaset's Security Advisory, as a reference to the authoritative and most up-to-date source of the information.
The right to use, redistribute, and modify the Gigaset Security Advisories is limited to the purpose of informing the third parties' own organization, its affiliates, or its customers about specific Gigaset Security Advisories.
Recognition and Rewards
Gigaset does not operate a bug bounty programme. Researchers who responsibly disclose valid vulnerabilities may be eligible for:
Public acknowledgement in Gigaset's Hall of Fame.
Rewards, where offered, are at the sole discretion of Gigaset and are contingent upon the reporter complying with this policy. Reports that violate the terms of this policy are not eligible for recognition.
Completion of the CVD process
The process is considered complete when:
- The report is deemed unfounded, or
- A vulnerability in an online service is fixed and publicly disclosed, or
- A patch is released and the vulnerability is disclosed, or
- The reporter does not respond for at least 30 days, or
- Mitigation is no longer feasible (in coordination with national CSIRT), or
- The vulnerability has been disclosed after the applicable timeline.
Gigaset informs the reporting entity about closure unless the report was anonymous.
Statutory reporting obligations (Cyber Resilience Act)
If a vulnerability is actively being exploited or there is a serious security incident during the support period:
- Early warning to the authorities ≤24 hours after becoming aware
- Full notification ≤72 hours
- Final report usually ≤14 days after provision of the fix of an actively exploited vulnerabiltty or
in case of a security inicident 1 month after the full notification to the single reporting platform.
Notification is made via the CRA Single Reporting Platform (SRP) operated by ENISA.
These statutory obligations exist in parallel with coordinated disclosure to users and the public.
Confidentiality & data management
Gigaset will treat vulnerability reports with confidentiality and will not share personal information provided by reporters with third parties without explicit consent, except where required by law.
Reporters who wish to remain anonymous may do so; however, anonymity may limit the Organization's ability to provide follow-up communications or recognition.
Review and Updates of this policy
This policy will be reviewed at least annually or following any significant change to Gigaset's products or regulatory environment. Updates will be published on Gigaset's website and communicated internally.
Any exceptions to this policy must be formally approved by the document owner and documented in the exceptions register. Exceptions are time-limited and subject to annual review.
Terms and abbreviations
| Term / abbreviation | Explanation |
|---|---|
| CSIRT | Computer Security Incident Response Team |
| CRA | Cyber Resiliance Act |
| CVD | Coordinated Vulnerability Disclosure |
| CVE | Common Vulnerabilities and Exposures |
| CVSS | Common Vulnerability Scoring System |
| ENISA | European Network and Information Security Agency |
| SRP | Single Reporting Platform |
| PST | Product Security Team |
| VDP | Vulnerability Disclosure Policy |
| VHP | Vulnerability Handling Policy |