Coordinated Vulnerability Disclosure

Security Support Center

LEGIC is committed to the security of its products and the customers who rely on them. We actively work with the security research community to identify, assess, and address vulnerabilities before they can impact our customers. We value the contributions of security researchers and our community in helping us maintain secure products and services for everyone who relies on us. If you have discovered a security vulnerability, we encourage you to disclose it to us quickly, and responsibly, to ensure the quality of our products and services is maintained.

LEGIC Security Advisories

Advisory ID Title Product Date
No security advisories have been published to date.

Responsible Disclosure

Responsible disclosure (also known as coordinated vulnerability disclosure, or CVD) ensures that findings of potential vulnerabilities in LEGIC products and services are addressed appropriately before impacting users. This process relies on the collaboration between LEGIC, those involved in discovery, and all stakeholders associated with the vulnerability. LEGIC is committed to industry best practices for CVDs and offers safe harbor to responsible contributors. If you have discovered a vulnerability and/or wish to participate in vulnerability disclosures and security research, please review the following guidelines and resources.

Transparency

LEGIC understands that vulnerabilities are discovered through various methodologies. Whether you are a customer, user of a LEGIC product or service, or a research professional, we are committed to working through the disclosure process with you. To enable an effective coordination throughout the response process, please be transparent about your goals, any desired timelines for public disclosure, and any information that may be important as LEGIC works to address all issues associated with the disclosure.

Vulnerability Reports

Vulnerability reports should include enough detail for LEGIC to replicate and validate all potential vulnerabilities, assess the potential risks, and properly prioritize mitigation efforts. Whenever possible, please include the following information in your vulnerability report:

  • Affected product(s) or service(s) and specific version(s) (if applicable)
  • Overview of how the vulnerability was discovered
  • Any proof-of-concept code or processes
  • Description or estimation of impact
  • Time constraints (e.g., date of planned public disclosure)
  • Any additional details related to the finding to help in the validation and risk assessment process

Providing the correct information can make all the difference in ensuring the proper response to all findings. If you believe some other details are essential in how LEGIC validates or responds to the associated vulnerability, please include them as well.

Please email your report and all associated information to the contact information provided below. For more information on best practices around vulnerability disclosures and reporting, please refer to the resources below or reach out to the LEGIC security team.

To securely provide your vulnerability report, please use the public PGP key under: www.legic.com/security.txt.

Public Disclosure

Time frames for type and schedule of disclosure may be affected by various factors, including, but not limited to,

  • risks to customers and users resulting from the vulnerability,
  • availability of effective mitigations, and
  • requirements by applicable laws and regulations.

Generally, vulnerabilities will be disclosed by LEGIC once patches or remediation steps are available to affected customers. It is critical that those who rely on affected products to protect their people, facilities, or property have adequate time to apply all fixes and mitigate any risks.

If there are timelines associated with non-LEGIC public disclosures (e.g., conference dates, publications, etc.), please let us know as soon as possible so LEGIC can plan accordingly.

Do No Harm

Ensure all testing and research efforts do not harm or disrupt production systems. This includes any activity that may expose sensitive data associated with affected systems. Please ensure that all local laws and product terms and conditions are followed and that you are aware of any consequences associated with the security research process.

If you have any concerns about the possible impact to systems, or questions about any data discovered during testing, please contact LEGIC’s security support.

Additional Resources

LEGIC recognizes industry standards and best practices throughout the CVD process. For more information on this process, please refer to the following resources.

CERT Guide →

CERT Guide to Coordinated Vulnerability Disclosure.

OWASP Cheat Sheet →

OWASP Vulnerability Disclosure Cheat Sheet Series.

Contact Us

For any security-related issues concerning LEGIC products or services, please contact us.

security@legic.com