Schließen
arrow-left-2arrow-left-3arrow-left-4arrow-leftchronodiggdown-arrow--lineardown-arrowearthenvelopefacebookfacebook_ (2)facebook_forward-arrowforwardgooglehomeico-downloadico-linkindustries--1industries--10industries--10_oldindustries--2industries--3industries--4industries--5industries--6industries--6_oldindustries--7industries--8industries--9linkedinmailmarkernewspaperpadlockpage-arrow-leftpage-arrow-rightpage-listpencilpinterestplay-buttonprintersearchsocial-diggsocial-facebooksocial-googlesocial-instagramsocial-linkedinsocial-pinterestsocial-twittersocial-youtubestartelephonetwittertwitter_user

Cyber Resilience Act (CRA) Regulation (EU) 2024/2847

MARPOSS Product Security and Vulnerability Disclosure (v.1.0)
Product Security Incident Response Team (PSIRT)


Marposs is committed to ensuring the cybersecurity, safety, and resilience of its products throughout their supported lifecycle.

The Marposs Product Security Incident Response Team (PSIRT) is responsible for receiving, assessing, coordinating, and managing reports of cybersecurity vulnerabilities affecting Marposs products, software, firmware, and related digital services. 

Our objective is to handle vulnerabilities in a timely, responsible, and coordinated manner and provide clear guidance on risk, mitigation, and remediation. 

Marposs supports responsible security research and welcomes reports submitted in good faith by customers, partners, security researchers, and other stakeholders. 



Scope 

The Marposs PSIRT handles reports concerning cybersecurity vulnerabilities affecting Marposs products or digital solutions. 

Examples include:

  • Industrial software products
  • Embedded software and firmware
  • Measurement and process control systems
  • Desktop, mobile, and web applications
  • Connected products with digital elements
  • Cloud or remote services that are part of a Marposs product offering
  • Security-related documentation errors that may impact the secure use of a product

The following are generally outside the scope of the Product Security Incident Response Team: 

  • Product support requests
  • Commercial or warranty issues
  • Feature requests
  • General technical assistance
  • Physical safety incidents unrelated to cybersecurity
  • Vulnerabilities affecting third-party products not supplied by Marposs

Requests outside the scope of PSIRT may be redirected to the appropriate Marposs support organization.



Reporting a Vulnerability

If you believe you have identified a potential cybersecurity vulnerability affecting a Marposs product, please report it to:

Email: psirt@marposs.com

To help us evaluate the report efficiently, please include whenever possible:

  • Product name and version
  • Affected component
  • Detailed description of the vulnerability
  • Steps required to reproduce the issue
  • Proof of concept, screenshots, logs, or supporting evidence
  • Estimated impact
  • Information regarding any known exploitation
  • Your contact details

Reports should be submitted in English whenever possible. 



Our Vulnerability Handling Process 

Marposs manages reported vulnerabilities through a structured process aligned with recognized coordinated vulnerability disclosure practices and internal product security procedures.

1. Acknowledgement, Assessment and Remediation

Upon receipt of a vulnerability report, Marposs undertakes the following actions:

  • Acknowledgement of receipt of the vulnerability report and assignment to the PSIRT and the relevant product security specialists.
  • Initial review and validation of the reported issue, including verification of the available evidence and, where necessary, a request for additional information.
  • Vulnerability determination to establish whether the reported issue constitutes a genuine cybersecurity vulnerability affecting a Marposs product or digital solution.
  • Severity and impact assessment, taking into account factors such as exploitability, known exploitation, customer exposure, deployment context, and industry-standard methodologies such as CVSS.
  • Identification of affected products, components, and versions, including an assessment of the scope of exposure.
  • Prioritization and coordination of remediation activities based on the assessed risk, impact, and urgency.
  • Development and validation of corrective or mitigating measures, where appropriate, which may include the form of security updates, software patches, firmware updates, configuration guidance, mitigation recommendations, or compensating controls.
  • Deployment or publication of the selected measures, together with the relevant implementation or update instructions where applicable.

2. Communication

When a vulnerability may affect customers or users, Marposs may issue security advisories containing:

  • Affected products and versions
  • Severity information
  • Available mitigations
  • Corrective actions
  • Update instructions

Where appropriate, Marposs may coordinate disclosure activities with the reporting party and with relevant authorities.

 

Responsible Disclosure Guidelines

Marposs encourages responsible and coordinated disclosure of vulnerabilities.

We ask security researchers to:

  • Report vulnerabilities confidentially through the PSIRT channel.
  • Allow reasonable time for validation and remediation before public disclosure.
  • Avoid actions that could disrupt customer operations, compromise data, or impact product availability.
  • Refrain from accessing, modifying, or destroying customer information.
  • Conduct research in compliance with applicable laws and regulations.

Marposs will not initiate legal action against individuals who conduct security research in good faith, within these guidelines, and without causing harm to customers, users, or Marposs systems.

Marposs does not currently operate a Bug Bounty award scheme.

 

Confidentiality and privacy

Marposs treats vulnerability reports as confidential information.

We ask you to provide with your name and contact details to facilitate further information sharing and to provide progress updates. Personal information provided by reporters will be processed in accordance with applicable privacy and data protection regulations and will not be disclosed without consent, unless required by law.
 

Regulatory Reporting

Where required by applicable legislation, Marposs may notify competent authorities regarding actively exploited vulnerabilities or severe incidents affecting products with digital elements and will communicate relevant security information to affected users where appropriate.

Security Advisories

When appropriate, Marposs may publish security advisories describing:

  • The vulnerability
  • Affected products
  • Severity
  • Available mitigations
  • Corrective versions
  • Update instructions

Advisories may also reference CVE (Common Vulnerabilities and Exposures) identifiers when available. 
 

Top Kontakt