Security
CVD Policy
Pinetek Networks GmbH takes the security of our products seriously. This page describes how to report a security vulnerability to us, what you can expect from that process, and lists advisories for vulnerabilities we have resolved — in line with our obligations under the EU Cyber Resilience Act (Regulation (EU) 2024/2847).
Reporting a Vulnerability
If you believe you have found a security vulnerability in any Pinetek Networks product, please report it to:
security@mail.pinetek-networks.com
Please include as much of the following information as possible:
- Product name and affected version(s)
- A description of the vulnerability and its potential impact
- Steps to reproduce, including any proof-of-concept code or screenshots
- Whether you are aware of the vulnerability being actively exploited
What to Expect
| Step | Timeframe |
|---|---|
| Acknowledgement of your report | Within 3 business days |
| Initial assessment (severity, affected products) | Within 5 business days |
| Status updates during remediation | At least every 2 weeks |
| Public advisory, once a fix is available | See below |
Our Commitment
- We will investigate all legitimate reports and do our best to quickly resolve confirmed vulnerabilities.
- We will keep you informed of our progress.
- We will credit you in the public advisory, if you wish to be credited.
- We ask that you give us a reasonable amount of time to resolve the issue before any public disclosure.
Safe Harbor
We consider security research conducted in accordance with this policy to be authorized. We will not pursue legal action against researchers who:
- Make a good-faith effort to avoid privacy violations, data destruction, and service interruption
- Do not access or modify data belonging to other users without permission
- Do not test against production systems in ways that could degrade service for our customers
- Report vulnerabilities to us directly and do not publicly disclose them before we have had a reasonable opportunity to address them
This policy does not cover third-party components or dependencies; if you find a vulnerability in an open-source component we use, we encourage you to also report it to the relevant upstream maintainer.
Security Advisories
Pinetek Networks GmbH publishes information on known and resolved security vulnerabilities in our products on this page, in line with our obligations under the EU Cyber Resilience Act (Regulation (EU) 2024/2847).
Details on our reporting process can be found in our Coordinated Vulnerability Disclosure Policy (see above).
Each advisory is published once a fix, workaround, or other corrective measure is available. Advisories are listed in descending order of publication date.
| ID | Title | Product | Severity | Published | Status |
|---|---|---|---|---|---|
| no entry available |