Product Vulnerability Reporting

The Rieter Group is committed to helping its customers’ operations remain safe and secure and continuously works to strengthen the security of its products and services. As part of these efforts, Rieter welcomes reports of suspected security vulnerabilities affecting its products and services. 

A product vulnerability is any error, weakness or flaw in a product or service that could be used to compromise its performance, integrity or availability, potentially leading to unauthorized access or breaches of confidentiality. By identifying and addressing such vulnerabilities, Rieter helps protect customer operations while improving the security of its products and services.

Rieter’s Product Security Incident Response Team (PSIRT, psirt(at)rieter.com) coordinates the assessment and handling of reported product vulnerabilities.

What to report

Product security vulnerabilities include potential security weaknesses affecting:

  • Rieter products, machines and controllers
  • Firmware, embedded software and applications
  • Product-related digital services, including cloud-based services
  • Web interfaces that are part of a product or service
  • Third-party components used within Rieter products where a vulnerability may affect the security of those products

You can report a suspected vulnerability even if its impact has not yet been fully verified or all affected versions are not yet known.

Information to include

Please include the following information, where available:

  • Affected product: Provide product name, model and firmware or software version.
  • Issue description: Describe what you discovered and the conditions under which it occurs.
  • Potential impact: Explain how the issue could affect security, safety or operation.
  • Reproduction details: Provide the steps necessary to reproduce the issue and relevant technical observations.
  • Supporting evidence: Send relevant screenshots, logs or an existing Common Vulnerabilities and Exposures (CVE) reference.
  • Observed exploitation: Inform whether you are aware of the issue being actively exploited.
  • Contact details: Tell us how we can reach you for a potential follow-up.

You can submit an initial report even if some details are unavailable.

 

How to submit your report

To report a vulnarability, either send an email to psirt(at)rieter.com.  

Suggested email subject: Product vulnerability report — [Product name / model]

Avoid including passwords, private keys, unnecessary personal information or confidential customer data. If supporting evidence requires a secure transfer method, contact us first to agree how to share it.

What happens next

PSIRT will review your report, assess the potential impact and coordinate the appropriate response. We may contact you for additional information and work with you on remediation and coordinated disclosure, where applicable. 

Responsible reporting

Please help us investigate safely.

  • Limit testing to what is necessary to demonstrate the issue.
  • Test only systems and environments for which you have appropriate authorisation.
  • Do not disrupt production, machine operation, safety functions or customer services.
  • Do not access, alter, delete or disclose data that is not yours.
  • Do not install malware or attempt to maintain access.
  • Stop testing if you encounter sensitive information or risk affecting operations, and report what you observed.
  • Coordinate with us before publicly disclosing technical details that could expose users to harm.

Operating this reporting channel does not grant authorization or permission to conduct security testing, scanning, or probing against Rieter or customer systems.

XS
SM
MD
LG
XLG