Vulnerability Reporting and Coordinated Disclosure
How to Report a Security Vulnerability
To report a security vulnerability affecting an Ellab product, solution, or infrastructure component, please send an email to prod_security@ellab.com.
Ellab is committed to coordinated vulnerability disclosure as required under the Cyber Resilience Act. We welcome vulnerability reports from security researchers, industry organisations, partners, customers, and other independent parties, whether or not you hold a service agreement with Ellab and regardless of the product’s lifecycle status.
A vulnerability does not need to have been actively exploited for it to be reported. Ellab encourages early reporting of any vulnerability that could reasonably be exploited, so that it can be assessed and addressed before it poses a risk to customers.
You do not need to sign a non-disclosure agreement (NDA) to submit a report. Ellab respects the interests and preferences of reporting parties, including requests for anonymity, and will handle all reports that are reasonably believed to be related to Ellab’s products, services, or infrastructure.
To help protect our customers and critical infrastructure, Ellab strongly encourages coordinated disclosure. This means allowing Ellab a reasonable period to analyze and remediate a reported vulnerability before any information about it is made public. Disclosing a vulnerability before a fix is available may expose customer systems to unnecessary risk.
What to Include in Your Report
To help us assess and address the issue effectively, please include the following information where available:
- A description of the vulnerability, including proof-of-concept (PoC) exploit code, screenshots, network traces, or other supporting evidence where available.
- The affected product, solution, service, or infrastructure component, including model numbers, software versions, and firmware versions if known.
- The current disclosure status of the vulnerability, including whether it has already been publicly disclosed.
- Detailed reproduction steps that allow Ellab to verify and reproduce the issue consistently.
Reports That Are Out of Scope
Please avoid reporting:
- Non-exploitable findings or configuration recommendations that do not present a practical security impact, such as missing HTTP security headers or suboptimal email configurations (SPF, DKIM, or DMARC).
- TLS configuration weaknesses, including support for older protocol versions (for example, TLS 1.0) or weak cipher suites, unless they are part of a demonstrable and exploitable security vulnerability.
What Happens After You Report
Once we receive your report, Ellab will review, investigate, and attempt to reproduce the reported vulnerability. If we need additional information, we will contact you for clarification or further technical details.
How Ellab Handles Confirmed Vulnerabilities
Confirmed vulnerabilities are managed through Ellab's vulnerability management process in collaboration with the relevant development and engineering teams.
During remediation, Ellab may stay in contact with the reporting party to:
- Provide status updates.
- Clarify technical details.
- Ensure mutual understanding of findings and remediation plans.
- Facilitate verification of proposed fixes.
Where appropriate, pre-release versions of security fixes may be shared with the reporting party for validation before public release.
Disclosure and Security Updates
If a vulnerability is confirmed, Ellab will develop and make available appropriate remediation measures — which may include security patches, updates, workarounds, or mitigating guidance — prioritised according to the severity and potential impact of the vulnerability.
Ellab will publish a Security Advisory when a confirmed vulnerability may affect customers and a remediation measure or mitigating action is available, or where early notification is necessary to allow customers to protect their systems. The timing and level of detail will depend on the severity of the vulnerability, the availability of a fix, and the risk of active exploitation.
Security Advisories are communicated through Ellab's established notification channels, including direct customer communications and publication on this website.
Ellab Security Advisories Typically Include
- A description of the vulnerability, including CVE references and severity ratings where applicable.
- Identification of affected products, services, software versions, and hardware versions.
- Information about mitigating factors, temporary workarounds, and recommended actions.
- Details on available patches, updates, or other remediation measures.
- Acknowledgment of the reporting party's contribution, subject to their consent.