Follow

Endian Vulnerability Disclosure Policy

Overview

Endian builds network security products for industrial and enterprise networks, so the security of those products is part of what we deliver. We welcome reports from anyone who finds a potential vulnerability in an Endian product, and we handle every report confidentially and in a documented, repeatable way.


Scope

This policy covers all currently supported Endian products and versions:

  • Endian 4i and Endian UTM Security Gateways
  • Endian Switchboard
  • Endian Network (cloud service)
  • Endian Connect App

It also covers third-party and open-source components shipped inside these products (see Third-party components).

It does not cover products or services from other vendors, even if they are used together with an Endian product. Please report those to the vendor concerned.


Product Security Incident Response Team (PSIRT)

When a report needs it, Endian convenes a Product Security Incident Response Team (PSIRT). The team includes people from quality assurance, development, operations and product management, plus the owners of the affected products. The PSIRT confirms and assesses the issue, coordinates the fix, keeps the reporter informed, and reports to the authorities where the CRA requires it.


How to report a vulnerability

Report security issues through the Endian Service Desk:

https://endian.atlassian.net/servicedesk/

  1. Once on the Endian Service site, choose "Product Security". Then choose:
    1.  "Report a security vulnerability" - If you have discovered or wish to report a security finding. 
    2.  "Report a security incident" - If an Endian product in your network has been, or may have been, compromised.
  2. Fill out the requested fields and attach any supporting files.
  3. Submit. You will receive a reference number for all further communication.

Confidentiality. Vulnerability reports are registered in a restricted security tracker and are seen only by the people handling the issue. If your report involves particularly sensitive material, such as working exploit code or data from a real system, say so in your request. We will then agree with you how to transfer it.

Personal data. Please do not include personal data unless it is needed to show the issue. We process any personal data we receive in line with the GDPR, and only to handle your report.
 

Please do not report vulnerabilities through public channels such as forums, social media, community boards or public issue trackers. Public posts can put other users at risk before a fix exists. Always use the Service Desk.

 

What happens after you report

Step What we do Our deadline
1. Acknowledgement We confirm receipt, give you a reference number and a contact for follow-up questions. Within 2 business days
2. Review We check whether the report affects an Endian product and try to reproduce it. If we need more information, we ask you. Within 5 business days of receipt
3. Clarification If we cannot reproduce the issue, we work with you to get what we need. If no further information arrives within 30 business days, we close the report and tell you why. 30 business days
4. Assessment We rate the severity, identify every affected product and version, and find the root cause. Prioritized by severity
5. Fix and communication We develop and test a fix, deliver it as a security update, and agree the disclosure date with you. Prioritized by severity
6. Closure We tell you the outcome and close the report. On resolution

We keep you informed at each step. Reports from national CERTs, CSIRTs and other coordinating bodies are acknowledged within 24 hours and go straight to a PSIRT.


How we prioritize

We rate every confirmed vulnerability with CVSS v4.0, the Common Vulnerability Scoring System maintained by FIRST. We calculate our own score even when the reporter supplies one, and we take into account how the product is typically deployed.

CVSS v4.0 base score How we treat it
7.0 – 10.0

Severe. Highest priority

This could trigger notifications to the relevant authority (CRA).

4.0 – 6.9 Fixed and publicly disclosed
below 4.0 Fixed; disclosed where the risk context justifies it

Any vulnerability that is being actively exploited gets top priority, whatever its score.

We set the public-disclosure threshold at 4.0, lower than many vendors do. Our products protect networks, so even a moderate issue can matter when it is combined with others.


Third-party and open-source components

If a vulnerability is in a third-party or open-source component we ship, we tell that component's maintainer through their official security reporting channel. We do this confidentially and coordinate the disclosure with them. We also check which Endian products and versions include the affected component.


Coordinated disclosure

We follow coordinated disclosure: we fix the issue and make the update available to customers before details are made public. Please do not publish details of a vulnerability until the fix is available or we have agreed a date with you. If you plan to publish your own research, tell us, and we will align the timing.

When we release a fix for a disclosed vulnerability, the release notes that come with the security update state:

  • the affected products and versions,
  • a description of the vulnerability and its impact,
  • the severity (CVSS v4.0),
  • the fixed version, and any workaround.

Where you need to act, for example to apply an update or a workaround, we also inform affected customers directly. We leave out details that would mainly help an attacker.

 

Reporting to the authorities (Cyber Resilience Act)

Since 11 September 2026, the CRA requires manufacturers to report certain vulnerabilities and incidents to the authorities. Endian submits these reports to ENISA / CSIRT through the EU single reporting platform. We report:

  • actively exploited vulnerabilities in our products, and
  • severe incidents affecting the security of our products.

We apply the same urgent handling to vulnerabilities we rate severe (CVSS 7.0 or higher).

Report Deadline
Early warning within 24 hours of becoming aware
Notification within 72 hours of becoming aware
Final report

Actively exploited vulnerability: within 14 days after the fix is available. 

Severe incident: within 30 days after the notification.

These authority reports are confidential. They do not replace the fix and the customer communication described above.
 

Acknowledgement

We appreciate the time researchers, our partners and customers invest in helping us improve our product.


Escalation

If you have not received an acknowledgement within 2 business days, or you are unhappy with how your report is being handled, add a comment to your Service Desk request asking for escalation. It will be raised to the head of the team responsible.


Legal notes (safe harbor)

We will not take legal action against anyone who finds and reports a vulnerability in good faith under this policy. We consider good-faith research that follows this policy to be authorized. In return, please:

  • test only against systems and data you own or are authorized to use,
  • avoid privacy violations, data destruction and service disruption; no denial-of-service tests,
  • do not use social engineering or physical attacks against Endian staff, customers or partners,
  • access or keep only the minimum data needed to show the issue, and delete it once the report is closed,
  • give us a reasonable chance to fix the issue before any public disclosure.

Actions that are malicious, cause harm, or break the law are not covered.


Disclaimer

Endian may update this policy at any time; the version published here is the current one. We handle every report under this policy but cannot guarantee a specific outcome or timeline for every issue.


Contact

Endian S.r.l., Via Ipazia 2, 39100 Bolzano (BZ), Italy. 

Have more questions? Submit a request

Comments