Coordinated Vulnerability Disclosure Policy
ILLIG packaging solutions GmbH
1. Purpose
The security of our products and the protection of our customers are important to ILLIG packaging solutions GmbH.
We welcome responsible reports of potential cybersecurity vulnerabilities affecting ILLIG products and associated digital services.
This Coordinated Vulnerability Disclosure (CVD) Policy describes how security researchers, customers, partners and other third parties can report potential security vulnerabilities to ILLIG and how we handle such reports.
Our objective is to investigate reported vulnerabilities in a coordinated manner, take appropriate measures to reduce security risks and, where necessary, provide affected customers with appropriate information and remediation measures.
2. Scope
This policy applies to potential cybersecurity vulnerabilities affecting ILLIG products with digital elements, associated software and digital services supplied or operated by ILLIG.
This includes, for example:
- machine control systems and PLCs;
- HMI systems;
- industrial PCs and operating systems;
- drive and automation systems;
- embedded software and firmware;
- network and remote-service components;
- software supplied as part of an ILLIG product;
- web applications and digital services associated with ILLIG products.
Vulnerabilities in third-party components integrated into an ILLIG product may also be reported to ILLIG.
This policy is intended for cybersecurity vulnerabilities. General technical problems, service requests or functional defects without a cybersecurity impact should be reported through the regular ILLIG service channels.
3. Reporting a Vulnerability
Potential security vulnerabilities should be reported to:
Please provide sufficient information to allow us to understand and reproduce the issue. Where available, please include:
- affected ILLIG product or machine type;
- serial number, if known;
- affected component;
- software or firmware version;
- detailed description of the vulnerability;
- steps required to reproduce the issue;
- potential security impact;
- information about whether active exploitation has been observed or is suspected;
- screenshots, log files or other relevant evidence;
- proof of concept, where appropriate;
- your name and contact details.
Please avoid including unnecessary personal, confidential or customer data in the report.
If sensitive information needs to be exchanged, please contact us first so that an appropriate communication method can be agreed.
4. What Happens After a Report
After receiving a vulnerability report, ILLIG will coordinate the assessment and handling of the reported issue.
-
Acknowledgement
We aim to acknowledge receipt of a security report within two business days. -
Initial assessment
ILLIG reviews the report and determines whether the reported issue represents a potential cybersecurity vulnerability and which products, versions or components may be affected. -
Technical investigation
Where necessary, ILLIG will reproduce and analyse the vulnerability and assess its potential security impact. -
Remediation
Depending on the results of the assessment, appropriate measures may include software or firmware updates, configuration changes, temporary workarounds, security recommendations, updates to documentation or other appropriate risk mitigation measures. -
Communication
We aim to provide the reporter with an initial assessment or status update within 10 business days, where reasonably possible. For complex vulnerabilities, investigation and remediation may require additional time. We will endeavour to keep the reporter informed of significant developments.
5. Coordinated Disclosure
ILLIG supports the coordinated disclosure of cybersecurity vulnerabilities.
We ask reporters to allow ILLIG reasonable time to investigate the vulnerability, develop and validate appropriate remediation measures and inform affected customers before details of the vulnerability are made public.
Where public disclosure is appropriate, ILLIG may coordinate the timing and content of the disclosure with the reporter.
Where appropriate or required by applicable law, ILLIG will provide information about remediated vulnerabilities. This may include a Security Advisory describing the affected products, potential security impact and available remediation or mitigation measures.
6. Responsible Security Research
When investigating a potential vulnerability in an ILLIG product or associated service, please act responsibly and avoid actions that could cause harm to customers, operators, production equipment or third parties.
In particular, please:
- do not intentionally disrupt the operation or availability of machines or systems;
- do not perform denial-of-service or similar disruptive testing;
- do not manipulate or disable safety-related functions;
- do not intentionally create unsafe machine conditions;
- do not modify or delete data unless strictly necessary to demonstrate the vulnerability;
- do not unnecessarily access, download or disclose personal, confidential or proprietary information;
- do not install malware or otherwise establish persistent access;
- do not attempt to access systems or data belonging to third parties without their authorization;
- limit testing to what is necessary to demonstrate and document the potential vulnerability.
If you unintentionally gain access to sensitive information or systems beyond what is necessary to demonstrate the vulnerability, please stop the investigation and inform ILLIG.
7. Good-Faith Security Research
ILLIG appreciates good-faith security research conducted responsibly and in accordance with this policy.
ILLIG does not intend to pursue legal action against researchers solely for good-faith security research that is performed in accordance with this policy and applicable law.
This does not authorize access to systems, machines or data without the permission of their respective owner or operator and does not waive the rights of third parties.
8. Confidentiality
ILLIG will handle vulnerability reports responsibly and will limit access to the information to persons involved in assessing, resolving or communicating the reported vulnerability, where reasonably possible.
Information provided by the reporter may be shared with relevant suppliers or technology partners where this is necessary to investigate or remediate the vulnerability.
Where required by applicable law, ILLIG will provide relevant information to competent authorities.
9. Recognition
If desired by the reporter and considered appropriate, ILLIG may acknowledge the reporter’s contribution in connection with a published Security Advisory.
Any such acknowledgement will be coordinated with the reporter before publication.
ILLIG does not currently operate a bug bounty programme, and submission of a vulnerability report does not create an entitlement to financial compensation.
10. Contact
Security vulnerabilities
ILLIG Product Security
product-security@illig.com
General technical and service requests
ILLIG Service
service@illig.com
Further information on how to contact ILLIG regarding security vulnerabilities is also available through: