ARI® Product Security Incident Response Team (PSIRT)

Report vulnerabilities | Coordinated disclosure of security advisories

Our commitment to product security

As a manufacturer of valves, we take the cyber security of our products seriously. Our Product Security Incident Response Team (PSIRT) is the central point of contact for all security-related reports concerning our products – from the initial assessment through to coordinated resolution.

Reporting a security incident or vulnerability

If you have discovered a security vulnerability or incident in one of our products, please inform us immediately.

You can contact us at psirt@ari-armaturen.com
 

What information should you provide?

Please include the following information in your report where possible:

  • Please include the following information in your report where possible:
  • Your contact details – name, email address and, optionally, telephone number. Anonymous reports are also possible; please note that in this case we will be unable to follow up with any queries.
  • Your organisation – If you are acting on behalf of a company or institution, please state this.
  • Affected product – Name of the ARI product in which you discovered the vulnerability. The following details are helpful: product name, order or serial number, firmware or software version, and the operating system of the components involved. For web-based services, please provide the relevant URL.
  • Description of the vulnerability – Describe the type of security vulnerability (e.g. insecure authentication, buffer overflow, hard-coded credentials, XSS) and the conditions under which it occurs.
  • Reproduction and evidence – Describe how the vulnerability can be exploited or the incident reproduced, and attach any supporting materials (e.g. logs, screenshots, proof-of-concept).
  • Observed impact – What is the worst-case scenario that could be achieved or caused by the vulnerability?
  • Disclosure status – Have you already reported the vulnerability to other parties, or are you planning to make it public? Please let us know so that we can coordinate our response accordingly.

We ask that you send us this information in encrypted form. Please use the following PGP key:

Download PGP key
Fingerprint: A3AD 3EC5 7D5D 2C4E B9E2  AAC8 265F 0F80 C53A C45B

As some of our products are used in critical infrastructure, coordinated vulnerability disclosure is particularly important. We therefore ask you to involve us before any public disclosure, so that we can develop and implement appropriate measures to remedy the issue or mitigate the risk.

 

How we handle reports

Once we have received your report, we will usually acknowledge it within two working days. Our PSIRT will then carefully review the information provided and assess the vulnerability using the industry-standard CVSS framework. If necessary, we will contact you to clarify any outstanding questions or to obtain further information. Once appropriate measures to rectify the issue or minimise the risk have been developed, we will coordinate with you on the timing and manner of publication as part of a coordinated disclosure process. Affected customers and users will then be informed accordingly.

We welcome all reports of vulnerabilities or security incidents in our products and recognise their contribution to improving product security. We ask that you do not publicly disclose the vulnerability until we have had sufficient opportunity to develop a remedy. Security researchers acting in good faith and adhering to the rules set out in this policy will not be subject to legal action on our part. We require that no data is misused or systems damaged, and that the reported vulnerability is treated confidentially; this does not constitute a waiver of any rights to which we are entitled.

Security advisories relating to ARI products and services

Here you will find all the latest security advisories issued by ARI PSIRT.