Secure. Transparent. Reliable: Product Security at Balluff
Report vulnerabilities—make solutions more secure.
Balluff stands for the highest standards of quality and safety—regardless of whether the products are software or hardware. To ensure this, transparency regarding potential vulnerabilities or error reports is essential. This is how we work together to make our products and solutions even better and safer.
The Balluff Product Security Incident Response Team (PSIRT) is the central point of contact for customers and partners to report security vulnerabilities in Balluff products.
Discovered a security vulnerability? Report it to us.
Please report the security vulnerability you’ve identified using the form below.
FAQ
-
Do you suspect a security vulnerability in a Balluff product?
Please report potential security vulnerabilities via email to [email protected] or via the form. Thank you for your support.
To securely exchange information and report vulnerabilities with the Balluff PSIRT, we provide this PGP key: https://keys.openpgp.org/vks/v1/by-fingerprint/9F37682BCD556E1B6156350299F474E854B32A93
Email: [email protected]
Name: Balluff PSIRT Team
Fingerprint: 9F37 682B CD55 6E1B 6156 3502 99F4 74E8 54B3 2A93 -
How do you receive security updates for your Balluff products?
Balluff provides security updates for its products exclusively through the Balluff Update Platform.
Links to the corresponding CVE numbers for published vulnerabilities can be found in the respective release notes.
For more information, features, and documentation on using the platform, click here: Balluff Update Platform.
-
Where are vulnerabilities affecting our products disclosed?
-
Why report security vulnerabilities?
By reporting vulnerabilities, you enable us to address them specifically and quickly inform affected customers about necessary measures. In this way, you actively contribute to making our products continuously more secure and better managing security risks.
-
Who can safely report and disclose potential security vulnerabilities?
Anyone can report potential security vulnerabilities via email to [email protected] or via the contact form to the Balluff PSIRT—regardless of whether a business relationship exists. A non-disclosure agreement (NDA) is not required for this.
Since our products are also used in sensitive infrastructure, uncoordinated disclosure can increase risks. Therefore, please always coordinate the publication of a vulnerability with the Balluff PSIRT.
-
What happens after you submit your report?
Your report will be made available exclusively to the Balluff Product Security Incident Response Team (PSIRT). Unauthorized internal or external parties will not have access to the information you submit. You are welcome to use the Traffic Light Protocol (TLP) for communication.
We always treat your identity and contact information as confidential. By default, we publish vulnerability reports anonymously. Your contact information will only be disclosed upon your express request.
All data is processed in accordance with Balluff’s applicable data protection regulations.
We will confirm receipt of your report within 2 business days. Within 10 business days, we will address the reported vulnerability in accordance with our Vulnerability Disclosure Policy and keep you informed of our progress.
Prioritization depends on the impact, severity, and complexity of the vulnerability. Therefore, resolution may take longer in some cases.
Once the vulnerability has been fixed, we will notify you and ask you to verify the fix.
-
What information do we need from you to process the security vulnerability report as quickly as possible?
Please provide us with as much information as possible. This includes:
Name of the reporter or organization
If you wish to remain anonymous, we will of course respect your request.
Affiliation of the reporter/discoverer
What is your organizational affiliation? If applicable and if you wish to share it.
Contact details
Please provide your email address and, if possible, your phone number so we can reach you.
What is the affected product?
If possible: Balluff order code and product name. Hardware version and firmware or software version. For services, please provide the relevant URL.
Type of Vulnerability
Please describe the type of vulnerabilities found (buffer overflow, XSS, authentication).
Detailed description of the vulnerability
How can you trigger the vulnerability? Can you provide us with proof (code samples demonstrating how the vulnerability can be exploited or a proof-of-concept)? Alternatively, can you provide recordings of network communications? (Attachments cannot be considered.)
Impact of the Vulnerability
Have you already disclosed the vulnerability, or do you have specific plans to disclose it?
CVSS Score
If known