Cybersecurity – Vulnerability Policy

Technical support

homeTechnical supportCybersecurity

Unitronics Vulnerability Handling and Coordinated Disclosure Policy

Purpose

This policy defines how Unitronics receives, evaluates, remediates, and discloses cybersecurity vulnerabilities affecting Unitronics products, firmware, software and supporting systems. The policy is aligned with the principles of the EU Cyber Resilience Act (CRA), ISO/IEC 29147, and ISO/IEC 30111.

1. Product Security Incident Response Team (PSIRT)

The Unitronics PSIRT is responsible for receiving vulnerability reports, coordinating technical investigations, assessing severity, managing remediation activities, coordinating regulatory reporting, and overseeing customer communications.

2. Vulnerability Reporting

Security vulnerabilities may be reported through the Unitronics support portal using the ‘Security Vulnerability’ category, through designated security contact channels, or through recognized CERT/CSIRT organizations. Reports should include affected product information, software or firmware versions, reproduction steps, impact details, and supporting evidence where available.

3. Initial Response and Triage

Reports are acknowledged, assigned a tracking identifier, reviewed for completeness, and evaluated for potential security impact. The PSIRT maintains communication with the reporting party throughout the investigation process.

4. Evaluation

Confirmed reports are assessed for exploitability, impact, customer exposure, and severity. Severity ratings are determined using CVSS and relevant product-specific considerations. Reports may be classified as confirmed vulnerabilities, duplicates, non-security issues, unsupported products, or insufficient information.

5. Remediation

Unitronics performs root-cause analysis, develops corrective actions, validates fixes, and prepares updates or mitigations as appropriate. Remediation priorities are based on vulnerability severity, exploitability, customer impact, and regulatory obligations.

6. Coordinated Disclosure

Unitronics works collaboratively with researchers, customers, CERTs, and other stakeholders to coordinate disclosure in a manner that minimizes customer risk.

Public disclosure is coordinated with the availability of mitigations, updates, or other protective measures whenever possible.

7. Security Advisories

When disclosure is required, Unitronics publishes security advisories containing vulnerability descriptions, affected products and versions, severity information, available mitigations, and remediation guidance.

8. CRA Reporting Obligations

Where required under the EU Cyber Resilience Act (CRA), Unitronics reports actively exploited vulnerabilities and severe incidents having an impact on the security of products with digital elements through the CRA Single Reporting Platform (SRP), within the applicable regulatory timeframes.

9. Researcher Safe Harbor

Unitronics supports responsible security research. Researchers acting in good faith, avoiding customer harm, respecting privacy, and following this disclosure process are considered to be participating in a coordinated disclosure effort.

10. Record Retention

Vulnerability reports, assessments, remediation records, advisories, and related communications are retained in accordance with regulatory requirements and Unitronics record-retention practices.