Coordinated Vulnerability Disclosure (CVD) Policy

1. Purpose

ELSA Srl regards the cybersecurity of its industrial machines as a fundamental element in ensuring reliability, operational continuity and the protection of its customers.


This Coordinated Vulnerability Disclosure (CVD) Policy sets out the procedures by which security researchers, customers, partners and other parties may report security vulnerabilities found in ELSA Srl products.


The aim is to facilitate the coordinated management of vulnerabilities, enabling their analysis, rectification and responsible disclosure in accordance with the Cyber Resilience Act (EU Regulation 2024/2847).

 

2. Scope

This policy applies to portable line boring machines designed and distributed by Elsa srl and its authorised distribution network.

How to report a vulnerability

Vulnerabilities must be submitted to the Product Security Incident Response Team (PSIRT).

We prefer contact via email using PGP encryption. The email address to use and the required PGP public key, including the fingerprint, are available in the information below:

 

Product Security Incident Response Team Contact Details

Email: pr**************@*****rl.com
PGP key: (Link to download the key)
Reporters are encouraged to provide as much technical information as possible.

To enable us to process your vulnerability report in a structured manner, we ask you to provide the following information.

To enable our Product Security Incident Response Team (PSIRT) to analyse and manage the reported vulnerability correctly, please provide the following information, where available:

Coordinated Disclosure

ELSA srl follows a Coordinated Vulnerability Disclosure process.
The customer is asked to:

  • not disclose the vulnerability publicly before ELSA srl has analysed and published a fix;
  • avoid any activity that could compromise the availability of the machine and the system;
  • not access or modify the machine;
  • cooperate with ELSA srl during the verification process.

 

ELSA Srl will maintain ongoing communication with the customer throughout all stages of vulnerability management. 

Vulnerability management process

Each report follows the process below:

  1. Registration of the vulnerability.

  2. Confirmation of receipt of the report.

  3. Technical analysis and verification of reproducibility.

  4. Severity assessment according to the CVSS methodology.

  5. Identification of affected products.

  6. Definition of corrective actions.

  7. Development and validation of the patch or mitigation.

  8. Publication of the Security Advisory.

  9. Release of the security update.

  10. Closure of the report.

 

Data protection

The information received will be processed solely for the purposes of managing the vulnerability and in accordance with Regulation (EU) 2016/679 (GDPR).