To Top
Schmersal IMPROVING PRODUCT SAFETY
Product Security Incident Response Team (PSIRT)

REPORTING SECURITY 
VULNERABILITIES

The security of our products, systems, and associated digital features is a top priority for us. If you have identified a potential security vulnerability in one of our products or in associated digital service, we ask that you report it to us responsibly.

This supports our processes for addressing vulnerabilities and continuously improving the cybersecurity of our products in accordance with applicable European requirements. 

RESPONSIBLE DISCLOSURE

We ask for coordinated and responsible disclosure. Specifically, this means: Please first inform us confidentially about the discovered vulnerability. Please give us reasonable time to review the report, assess risks, and implement appropriate corrective measures. 

Please do not publish any details before we have jointly agreed on a disclosure date or until appropriate countermeasures are in place.

HOW TO REPORT VULNERABILITY

Please send your report to:

psirt@dont-want-spam.schmersal.com

Please include the following information, if possible:

  • Affected product(s), part number, software/firmware version
  • Description of the suspected vulnerability
  • Technical environment specifications
  • Steps to reproduce the issue
  • Evidence / Proof of Concept, if available and can be provided securely
  • Possible impacts on confidentiality, integrity, availability, and, if applicable, on the product’s security features
  • Your contact information for follow-up questions
  • Information on whether the vulnerability has already been reported to third parties or made public. 

Upon receipt of your report, we will:

  • confirm receipt of your report,
  • analyze and evaluate the reported vulnerability,
  • examine the affected products, features, and, if applicable, security implications,
  • determine the necessary corrective, mitigating, or update measures,
  • We will keep you informed – provided we have your contact information – of the status of the process to the extent possible

To the extent required by law or objectively necessary, we will also take internal and external follow-up actions as part of our regulatory and product safety processes.

SCOPE 

This reporting channel is intended for reports on cybersecurity vulnerabilities in our products that include digital elements, accompanying software, firmware, communication interfaces, update mechanisms, or associated digital services. If vulnerability could affect safety-critical machine functions or safety-related components, this will be addressed separately in our internal assessment and handling processes.

CONFIDENTIALITY AND DATA PROTECTION 

We treat incoming reports confidentially and use the information provided exclusively to investigate, assess, and address the reported vulnerability, as well as to comply with any legal obligations. Please do not submit any personal data unless it is necessary for the report.
 

Cookies / Privacy Policy
We respect your privacy
This website uses cookies. Further information on the cookies used can be found in our data protection declaration. By clicking on the "Accept all" button, you consent to the use of all of these cookies. By clicking the "Accept selected" button, you only consent to the use of cookies for the purposes you have selected.
Your choice: