At ESR, we take product security seriously and recognize the importance of protecting user privacy and data. We are committed to identifying and addressing security issues to help protect our users.
We welcome security reports from customers, suppliers, independent researchers, security organizations, and other interested parties. All reports will be handled in accordance with our established vulnerability management process, and we will provide timely updates where appropriate.
Reporting a Vulnerability to ESR
We strongly encourage organizations and individuals who identify a potential security issue affecting an ESR product to report it to the ESR Security Team.
Security vulnerabilities can be reported by email at cybersecurity@esrtech.com.
Please include at least the following information in your report:
-
Your organization and contact information
-
The affected product and version
-
A description of the potential vulnerability
-
Any known information relating to the vulnerability
-
Your intended disclosure timeline
-
Any other information that may assist our investigation
Providing as much relevant detail as possible will help ESR assess and investigate the reported vulnerability more quickly and accurately.
Security Vulnerability Reporting Guidelines
-
All parties involved in vulnerability disclosure must comply with the applicable laws and regulations of their respective countries or regions.
-
Vulnerability reports should be based on the latest publicly released firmware version and should preferably be submitted in English.
-
Please report vulnerabilities through the designated communication channel above. ESR may receive reports submitted through other channels, but we cannot guarantee that such reports will be acknowledged or processed promptly.
-
When conducting vulnerability research or testing, you must respect applicable data protection requirements and must not compromise the security, privacy, integrity, or availability of data, services, systems, employees, representatives, or users associated with ESR.
-
We ask researchers and other reporting parties to maintain open communication and cooperate with ESR throughout the disclosure process, and not to publicly disclose vulnerability information before the mutually agreed disclosure date.
-
ESR does not currently operate a vulnerability bounty program.
How ESR Handles Vulnerabilities
ESR encourages customers, suppliers, independent researchers, security organizations, and other interested parties to proactively report potential vulnerabilities to our Security Team. We also monitor relevant security communities, vulnerability databases, and security-related websites for information concerning potential vulnerabilities affecting ESR products.
We aim to acknowledge receipt of a vulnerability report within 1 business day and conduct an initial assessment. We aim to complete the assessment within 3 business days, after which the vulnerability will either be remediated or a remediation plan will be established.
Our target remediation timelines are as follows:
-
Critical-risk vulnerabilities: within 3 business days
-
High- and medium-risk vulnerabilities: within 30 business days
-
Low-risk vulnerabilities: within 180 business days
Please note that remediation timelines may vary depending on factors such as technical complexity, hardware limitations, and the environment in which the affected product operates. Actual remediation timelines will therefore be determined on a case-by-case basis.
Security Update Support Period
We are committed to providing ongoing security updates for our products. For certain product models, ESR will provide security update support for at least 5 years from the date the product is first placed on the market.
Updates to This Product Security Policy
We may update this Product Security Policy from time to time. We encourage you to review this page periodically for the latest information.
When changes are made, the revised version and its effective date will be published on this page.
Contact Us
If you have any questions or comments regarding product security or this Product Security Policy, please contact us at cybersecurity@esrtech.com.
If you have a complaint or concern regarding this Product Security Policy, you may also contact us using the email address above. We take all product security concerns seriously and will review your submission and respond within a reasonable timeframe.