Product Security Incident Response Team (PSIRT)

About PSIRT

The ARIES Embedded Product Security Incident Response Team (PSIRT) supervises the process of accepting and responding to reports of potential security vulnerabilities involving products by ARIES Embedded.

If you wish to report a potential security vulnerability regarding our products, we encourage you to report it to the ARIES Embedded PSIRT by following the steps described on this page.


How to report a potential security vulnerability

To report a potential security vulnerability, please contact our PSIRT at psirt@aries-embedded.de.

All exchanges and reports must be provided in English.

Because of the sensitive nature of such reporting, PSIRT highly encourages all potential security vulnerability reports to be sent encrypted, using the PSIRT PGP/GPG Key:

  • Fingerprint: 5D69 3D4F F9BE BBE1 932C 7AD8 74C4 76A6 5A62 513A
  • Public Key File (asc, 3,3 KB)

Free software to read and author PGP/GPG encrypted messages may be obtained from:

  • Gpg4win
  • GnuPG

IMPORTANT-READ CAREFULLY:
ARIES Embedded GmbH, on behalf of itself, its affiliates and subsidiaries, takes all potential security vulnerability reports or other related communications (“Report(s)”) seriously. In order to review Your Report (the terms “You” and “Yours” include your employer, and all affiliates, subsidiaries and related persons or entities) and take actions as deemed appropriate, ARIES Embedded GmbH requires that we have the rights and Your permission to do so.

As such, by submitting Your Report to ARIES Embedded GmbH, You agree that You have the right to do so, and You grant to ARIES Embedded GmbH the rights to use the Report for purposes related to security vulnerability analysis, testing, correction, patching, reporting and any other related purpose or function.


Potential vulnerability management process

Once submitted, PSIRT will manage the reported potential security vulnerability according to the following process:

  1. Reporting a new vulnerability: At this stage, PSIRT will acknowledge receipt of the reported issue.
  2. Evaluating: PSIRT will evaluate the potential vulnerability to understand if there is an issue, analyze it, and set a priority to manage valid issues.  PSIRT may come back to the submitter in case some information is missing from the original report or if clarification is needed.
  3. Solving: PSIRT will investigate potential solutions and mitigations to address valid issues.
  4. Communicating: Once a solution is available (fix or mitigation), PSIRT will communicate back to the submitter and others where appropriate.