Products
Service & Support
Industries & Solutions
Career
Company

Secure. Transparent. Reliable: Product Security at Balluff

Report vulnerabilities—make solutions more secure.

Balluff stands for the highest standards of quality and safety—regardless of whether the products are software or hardware. To ensure this, transparency regarding potential vulnerabilities or error reports is essential. This is how we work together to make our products and solutions even better and safer. 

The Balluff Product Security Incident Response Team (PSIRT) is the central point of contact for customers and partners to report security vulnerabilities in Balluff products. 

Discovered a security vulnerability? Report it to us.

Please report the security vulnerability you’ve identified using the form below.
Go to the form


FAQ

  • Do you suspect a security vulnerability in a Balluff product?

    Please report potential security vulnerabilities via email to [email protected] or via the form. Thank you for your support.

    To securely exchange information and report vulnerabilities with the Balluff PSIRT, we provide this PGP key: https://keys.openpgp.org/vks/v1/by-fingerprint/9F37682BCD556E1B6156350299F474E854B32A93

    Email: [email protected]
    Name: Balluff PSIRT Team
    Fingerprint: 9F37 682B CD55 6E1B 6156 3502 99F4 74E8 54B3 2A93

  • How do you receive security updates for your Balluff products?

    Balluff provides security updates for its products exclusively through the Balluff Update Platform.

    Links to the corresponding CVE numbers for published vulnerabilities can be found in the respective release notes.

    For more information, features, and documentation on using the platform, click here: Balluff Update Platform.

  • Where are vulnerabilities affecting our products disclosed?

    The Balluff PSIRT publishes vulnerabilities related to Balluff products via CERT@VDE.

    These disclosures are based on the CSAF. All vulnerability reports are also available via an RSS feed.

  • Why report security vulnerabilities?

    By reporting vulnerabilities, you enable us to address them specifically and quickly inform affected customers about necessary measures. In this way, you actively contribute to making our products continuously more secure and better managing security risks.

  • Who can safely report and disclose potential security vulnerabilities?

    Anyone can report potential security vulnerabilities via email to [email protected] or via the contact form to the Balluff PSIRT—regardless of whether a business relationship exists. A non-disclosure agreement (NDA) is not required for this.

    Since our products are also used in sensitive infrastructure, uncoordinated disclosure can increase risks. Therefore, please always coordinate the publication of a vulnerability with the Balluff PSIRT.

  • What happens after you submit your report?

    Your report will be made available exclusively to the Balluff Product Security Incident Response Team (PSIRT). Unauthorized internal or external parties will not have access to the information you submit. You are welcome to use the Traffic Light Protocol (TLP) for communication.

    We always treat your identity and contact information as confidential. By default, we publish vulnerability reports anonymously. Your contact information will only be disclosed upon your express request.

    All data is processed in accordance with Balluff’s applicable data protection regulations.

    We will confirm receipt of your report within 2 business days. Within 10 business days, we will address the reported vulnerability in accordance with our Vulnerability Disclosure Policy and keep you informed of our progress.

    Prioritization depends on the impact, severity, and complexity of the vulnerability. Therefore, resolution may take longer in some cases.

    Once the vulnerability has been fixed, we will notify you and ask you to verify the fix.

  • What information do we need from you to process the security vulnerability report as quickly as possible?

    Please provide us with as much information as possible. This includes:

    Name of the reporter or organization

    If you wish to remain anonymous, we will of course respect your request.

    Affiliation of the reporter/discoverer

    What is your organizational affiliation? If applicable and if you wish to share it.

    Contact details

    Please provide your email address and, if possible, your phone number so we can reach you.

    What is the affected product?

    If possible: Balluff order code and product name. Hardware version and firmware or software version. For services, please provide the relevant URL.

    Type of Vulnerability

    Please describe the type of vulnerabilities found (buffer overflow, XSS, authentication).

    Detailed description of the vulnerability

    How can you trigger the vulnerability? Can you provide us with proof (code samples demonstrating how the vulnerability can be exploited or a proof-of-concept)? Alternatively, can you provide recordings of network communications? (Attachments cannot be considered.)

    Impact of the Vulnerability

    Have you already disclosed the vulnerability, or do you have specific plans to disclose it?

    CVSS Score

    If known

Energy consumption labeling
Energy consumption labeling

EPREL - European Product Database for Energy Labeling

Do you have any questions or suggestions? We are at your disposal.

For all questions concerning commercial topics such as quotations, orders, delivery times, our inside sales department will be happy to support you.

Contact us directly by phone: +49 7158 173-555


Balluff GmbH

Zabergäustraße 8
73765 Neuhausen a.d.F.

Free sample product

In order to add a free sample product to the cart we will need to remove all the normal products from the cart. Are you sure you want to continue