ITW EAE Support Center

Coordinated Vulnerability Disclosure (CVD) Policy

Scope 

This policy applies to security vulnerabilities found in ITW EAE products and associated services that are in the Current Product or Stability phase of their lifecycle.  Please refer to the Product Life Cycle documentation. Some products carry additional regulatory obligations (e.g., the EU Cyber Resilience Act); where they do, those obligations also apply.  

 

How to Report a Vulnerability 

Report vulnerabilities through our Support Center site using the Submit Ticket option. 

 

What to Include 

To help us investigate efficiently, please include as many of the following as you can: 

  • Affected product name, model number, and firmware/software version affected 
  • Description of the vulnerability and its potential impact 
  • Step-by-step reproduction instructions, proof-of-concept code, or scripts (if available) 
  • Whether you believe the vulnerability is being actively exploited in the wild 
  • Your contact information and time zone 

 

What to Expect from Us 

  • Acknowledgement – We will acknowledge your report upon submission and provide an initial status update within a few business days.  
  • Timeline – We will prioritize remediation based on assessed severity and risk. We aim to address vulnerabilities without undue delay, considering the complexity of the fix, any required coordination with upstream suppliers, and the need to test changes before release.  We assess vulnerabilities using CVSS v3.1 or a successor standard. 
  • Embargo & Disclosure – We do not disclose vulnerability details before a fix or adequate mitigation is available, except where active exploitation necessitates early advisory guidance to protect affected users. When appropriate, we will request or coordinate the assignment of a CVE identifier. 
  • Active Exploitation - If we confirm active exploitation of a vulnerability, we will issue an early advisory with mitigation guidance while the full fix is in development. 
  • Safe Harbor - If you act in accordance with this policy, conduct research in good faith, avoid privacy violations and service disruption, and promptly report findings to us, we will not initiate legal action against you for security research conducted in compliance with this policy. 
  • Product Updates – Security updates addressing vulnerabilities are provided free of charge. 
  • Recognition - With the reporter's consent, we may acknowledge their contribution in public security advisories. 
  • Third Party Components - If a reported vulnerability originates from a third-party component, we will coordinate with the affected supplier as appropriate and keep the reporter informed of significant developments. 

 

What We Ask of Submitters 

We ask that you act in good faith: 

  • We generally request a 90-day coordinated disclosure period before public disclosure, although timelines may be adjusted based on severity, exploitation status, remediation complexity, or mutual agreement with the reporter. 
  • Do not exploit the vulnerability beyond what is necessary to demonstrate it — this includes not accessing, modifying, or deleting data belonging to other users. 
  • Do not degrade or disrupt services (e.g., denial of service testing). 
  • Do not use attacks on physical security, social engineering, distributed denial of service, spam, or applications of third parties. 
  • Comply with applicable laws during your research. 

 

EU Cyber Resilience Act Compliance 

Certain ITW EAE products sold in the European Union are subject to the EU Cyber Resilience Act (CRA), where applicable. In-scope products are determined by product-by-product scoping analysis. For in-scope products, we comply with the applicable vulnerability handling and reporting obligations of the CRA, where applicable, including obligations to notify relevant authorities when actively exploited vulnerabilities are identified.

K
Ken is the author of this solution article.

Did you find it helpful? Yes No

Send feedback
Sorry we couldn't be helpful. Help us improve this article with your feedback.