Product Security

Product Security Incident Reporting

DATRON encourages coordinated vulnerability disclosure and asks reporters to provide DATRON with a reasonable period to investigate and remediate reported vulnerabilities before public disclosure. Where required under applicable legislation, including the EU Cyber Resilience Act, DATRON will fulfill its obligations regarding vulnerability handling, documentation, and reporting to relevant authorities.

Please submit vulnerability reports and security-related information to: product-security@datron.de

DATRON is committed to handling all reports confidentially and in accordance with applicable legal and regulatory requirements, including the EU Cyber Resilience Act (CRA). We encourage responsible and coordinated vulnerability disclosure to help protect our customers, partners, and products. A Non-Disclosure Agreement (NDA) is not required to report a security vulnerability or to cooperate with DATRON during the disclosure and remediation process. DATRON does not currently operate a bug bounty program unless otherwise stated.

Information to include in your report

To help us assess and address reported vulnerabilities efficiently, please provide as much of the following information as possible:

Reporter information:

  • Name of the reporter (optional; anonymous reports are accepted)
  • Email address and telephone number for follow-up communication
  • Organization, company, or affiliation (if applicable)

 Vulnerability details:

  • Type of vulnerability: Describe the vulnerability category (for example, cross-site scripting (XSS), buffer overflow, authentication bypass, hard-coded credentials, privilege escalation, denial of service, or other).
  • Proof of Concept (PoC): Include any code, scripts, screenshots, logs, packet captures (PCAPs), or step-by-step instructions that demonstrate or reproduce the issue.
  • Observed impact: Describe the actual or potential security impact, including effects on confidentiality, integrity, availability, safety, or operational performance.
  • Affected products and components: Identify the affected DATRON products, software, firmware, services, or components. Please include relevant version numbers, configurations, serial numbers (where applicable), and service URLs or deployment environments.
  • Reproduction instructions: Provide sufficient information to reproduce the issue consistently.
  • Disclosure status: Indicate whether the vulnerability has already been publicly disclosed, reported to any third party, or is subject to planned public disclosure.

DATRON will acknowledge receipt of your report within three (3) business days. We appreciate the efforts of security researchers, customers, partners, and other stakeholders who help improve the cybersecurity and resilience of DATRON products and services. Your responsible reporting contributes to the ongoing protection of our customers and supports DATRON's commitment to cybersecurity, product security, and compliance with applicable European cybersecurity regulations.

Search Datron.de
X