Wählen Sie ein anderes Land oder eine andere Region, um Inhalte für ihren Standort zu sehen

Cyber security at HEIDENHAIN

At HEIDENHAIN, cyber security is a key pillar of our corporate philosophy and is firmly anchored in our processes. We are committed to protecting our products, systems, and data across their entire life cycle.

An important part of our security strategy is the responsible handling of potential vulnerabilities. The systematic collection, assessment, and remediation of vulnerabilities is integral to our vulnerability management process.

Report a product vulnerability Visit CERT@VDE
[Translate to English:] PSIRT

Reporting vulnerabilities

We welcome collaboration with security researchers, customers, and other stakeholders. This page explains the procedure for reporting identified vulnerabilities in accordance with our disclosure policy. We aim to handle reported vulnerabilities in a transparent, efficient, and responsible manner in order to continuously improve the security of our solutions. To facilitate communication to this end, we participate in the CERT@VDE IT security/cyber security network of the VDE. 

 

Our Coordinated Vulnerability Disclosure (CVD) policy

The security of our products is a top priority at HEIDENHAIN. We have a systematic process for handling reported security vulnerabilities regarding our products, solutions, and IT infrastructure, and collaborate closely with anyone who reports vulnerabilities. Complying with, continuously monitoring, and implementing regulatory requirements, such as the Cyber Resilience Act (CRA), are an integral part of our cyber security management process.

The following guidelines explain how vulnerabilities can be reported and how we handle them.

These guidelines apply to all products offered by HEIDENHAIN, regardless of whether they are subject to servicing agreements and regardless of their status within the product life cycle.

We welcome reports from any source: researchers, trade associations, CERTs, partners, or third parties. We do not require a confidentiality agreement as a condition for accepting reports.

If your report is about our digital infrastructure (e.g., our website or active services), please send us an email to security@heidenhain.com.

HEIDENHAIN will not take legal action against reporting individuals if the following conditions are met:

  • No harm to individuals
  • Testing only to the extent necessary to verify a vulnerability
  • Testing on productive systems only with explicit authorization
  • No impairment of availability (no DoS attacks), no social engineering, and no access to physical infrastructure
  • Access only to the data required for demonstration purposes; no modification, deletion, or exfiltration of data
  • Protection of the security and privacy of others
  • Compliance with applicable laws
  • Willingness to coordinate disclosure (no public disclosure before the expiry of a mutually agreed period)

We value your reports and their ability to help us quickly remediate problems.

 

 

 

  • Notify us as early as possible about actual or potential security problems.
  • Use exploits only to the extent necessary to verify the vulnerability.
  • Give us sufficient time to remediate the problem. We will publish significant and confirmed vulnerabilities through CERT@VDE.
  • Immediate public disclosure would create a “zero-day” situation and would expose our customers' systems, including critical infrastructure, to unnecessary risks. We therefore strongly request coordinated disclosure.

 

  • To send a detailed vulnerability report, along with any related files and confirming evidence, please use our cyber security contact form.
  • Email: product-security@heidenhain.com (The email addresses stated in our security.txt are intended solely for initial contact and are not to be used for sending sensitive or detailed information regarding vulnerabilities.)
  • Reporting through CERT@VDE: https://www.certvde.com/en/service/report-a-vulnerability/ 

 

If possible, please provide the following information:

  • The affected product or software (including ID number and software or firmware version)
  • Description of the vulnerability, where it was found, and its potential effects
  • Any reproducible steps (PoC, scripts, screenshots, network data)
  • Whether or not the vulnerability is already public knowledge
  • Any relevant documents (CVE, notifications, release notes) 
  • Preferably a description in English
  1. Report received: We provide confirmation that the report was received.
  2. Assessment: We examine and reproduce the vulnerability, requesting more information if needed.
  3. Handling: We coordinate remediation and keep you informed.
  4. Public disclosure: As soon as a solution is available or has been published (whichever occurs first), we will publish a security advisory. CVE entries will be created in coordination with CERT@VDE and published in accordance with the CSAF.

Our security advisory will usually contain the following information:

  • A description of the vulnerability with a CVE reference and CVSS score
  • Any affected products and versions
  • Information about workarounds and risk-reducing measures
  • Information about available updates/fixes

     

Contact us

If you would like to report a vulnerability, request information, or have any questions, then please feel free to contact us.

Product vulnerabilities CERT@VDE Information security