Coordinated Vulnerability Disclosure Policy

ILLIG packaging solutions GmbH

1. Purpose

The security of our machines, software and digital services and the protection of our customers are important to ILLIG packaging solutions GmbH.

We welcome responsible reports of potential cybersecurity vulnerabilities affecting ILLIG products and associated digital services.

This Coordinated Vulnerability Disclosure (CVD) Policy explains how security researchers, customers, partners and other third parties can report potential cybersecurity vulnerabilities to ILLIG and how we handle such reports.

Our objective is to investigate reported vulnerabilities, assess their potential impact and provide appropriate remediation or mitigation measures where needed.

2. Scope

This policy applies to potential cybersecurity vulnerabilities affecting ILLIG machines and products with digital elements, including software and digital services supplied or operated by ILLIG.

Relevant components may include:
•    machine control systems and PLCs;
•    HMI systems;
•    industrial PCs and operating systems;
•    drive and automation systems;
•    embedded software and firmware;
•    network interfaces and remote-service components;
•    software supplied as part of an ILLIG machine or system;
•    web applications and digital services associated with ILLIG products.

Vulnerabilities in third-party hardware or software integrated into an ILLIG product may also be reported to ILLIG. If required, we will coordinate the investigation with the respective supplier or technology partner.

This policy is intended specifically for cybersecurity vulnerabilities. Machine malfunctions, service requests, spare-parts inquiries and functional defects without a cybersecurity impact should be reported through the regular ILLIG service channels.

3. Reporting a Vulnerability

Potential cybersecurity vulnerabilities should be reported to:
ILLIG Product Security
ILLIG packaging solutions GmbH
product-security@illig.com

Please provide enough information to help our Product Security team and technical specialists understand and, where possible, reproduce the issue.
Useful information includes:
•    affected ILLIG product or machine type;
•    machine serial number, if known;
•    affected hardware or software component;
•    software or firmware version;
•    description of the vulnerability;
•    steps to reproduce the issue;
•    potential cybersecurity impact;
•    information on observed or suspected active exploitation;
•    screenshots, log files or other relevant evidence;
•    proof of concept, where appropriate;
•    your name and contact details.

Please avoid including unnecessary personal, confidential or customer data.

If sensitive information, machine data or technical documentation needs to be exchanged, please contact us first so that an appropriate communication method can be agreed.

4. What Happens After a Report

After receiving a vulnerability report, ILLIG coordinates the assessment and involves the relevant technical specialists as required.

  1. Acknowledgement: We aim to acknowledge receipt of a security report within two business days.
  2. Initial assessment: We review the report to determine whether it represents a potential cybersecurity vulnerability and identify the products, software versions or components that may be affected.
  3. Technical investigation: The responsible specialists analyse the issue and, where possible, reproduce it. The investigation considers the potential cybersecurity impact and the conditions required for exploitation.
  4. Remediation:Depending on the assessment, measures may include software or firmware updates, configuration changes, temporary workarounds, security recommendations or documentation updates.
  5. Communication: We aim to provide the reporter with an initial assessment or status update within 10 business days, where reasonably possible. Complex issues, particularly those involving machine-specific configurations or third-party components, may require additional investigation. In such cases, we will keep the reporter informed of significant developments.

5. Coordinated Disclosure

ILLIG supports the coordinated disclosure of cybersecurity vulnerabilities.

We ask reporters to allow sufficient time for ILLIG to investigate the vulnerability, identify affected products or versions, develop and validate appropriate measures and inform affected customers before technical details are made public.

The appropriate form of communication depends on the nature and potential impact of the vulnerability. In many cases, direct communication with affected customers may be the most appropriate way to provide remediation or mitigation measures.

Where public disclosure is appropriate or required, ILLIG may publish a Security Advisory and coordinate the timing and content with the reporter and relevant technology partners.

A Security Advisory may include information about affected products or software versions, the potential cybersecurity impact and available remediation or mitigation measures.

6. Responsible Security Research

ILLIG machines are industrial systems that may be used in production environments. Security testing must therefore be conducted carefully to avoid unintended effects on machines, production processes, operators or third parties.

When investigating a potential vulnerability, please:
•    do not intentionally disrupt machines or systems;
•    do not perform denial-of-service or similar disruptive testing;
•    do not manipulate, bypass or disable safety-related functions;
•    do not intentionally create unsafe machine states or operating conditions;
•    do not modify or delete machine, production or other data unless necessary to demonstrate the vulnerability;
•    do not unnecessarily access, download or disclose personal, confidential or proprietary information;
•    do not install malware or establish persistent access;
•    do not access machines, systems or data belonging to third parties without authorization;
•    limit testing to what is necessary to demonstrate and document the potential vulnerability.

Testing on machines in active production should only be performed with the authorization of the machine owner or operator and with appropriate consideration of operational and safety risks.

If you unintentionally gain access to sensitive information or other systems beyond what is necessary to demonstrate the vulnerability, please stop the investigation and inform ILLIG.

7. Good-Faith Security Research

ILLIG appreciates good-faith security research conducted responsibly and reported in accordance with this policy.
ILLIG does not intend to pursue legal action against researchers solely for good-faith security research performed in accordance with this policy and applicable law.

This policy does not authorize access to machines, systems, networks or data without permission from their owner or operator and does not waive the rights of customers or other third parties.

8. Confidentiality

ILLIG will handle vulnerability reports responsibly and limit access to employees and external specialists who need the information to assess, investigate or remediate the vulnerability.
Relevant technical information may be shared with technology suppliers where needed to investigate or remediate a vulnerability.
Where required by law, ILLIG will provide relevant information to competent authorities.

9. Recognition

If desired by the reporter and considered appropriate, ILLIG may acknowledge the reporter’s contribution in a published Security Advisory. Any acknowledgement will be coordinated with the reporter before publication.
ILLIG does not currently operate a bug bounty programme. Submitting a vulnerability report therefore does not create an entitlement to financial compensation.
 

Contact


Security vulnerabilities
ILLIG Product Security: product-security@illig.com

General technical and service requests
ILLIG Service: service@illig.com

Further information on how to contact ILLIG regarding security vulnerabilities is also available through:

https://www.illig.com/.well-known/security.txt
 

Merkzettel
Lösungen
Service
Standorte & Kontakt
Youtube