Product security and vulnerability management at HERMLE AG
Maschinenfabrik Berthold HERMLE AG sets the highest of standards for the cybersecurity, product security and resilience of its machining centres, automation solutions and digital systems.
A key element of this claim is PSIRT.
This team is responsible for the structured management of security risks throughout the entire product life cycle.
Process for reporting security vulnerabilities
Optionally via CERT
For reporting product-specific vulnerabilities (incl. encrypted communication and the option to report anonymously)
To report a vulnerability CERT@VDE
Recommended report content
To ensure a report is dealt with quickly, include the following information:
- Affected product / component (machine number, software version(s), Hermle article number, order number, manufacturer).
- A detailed description of the vulnerability and the steps required to reproduce it. If known, the conditions that must be satisfied for the vulnerability to be exploited.
- Proof of Concept, such as a concept script, screenshot or similar supporting material (optional).
- If known, the potential consequences (e.g., loss of availability, breach of integrity, compromise of safety).
- If available, documents relating to the security vulnerability (CVE, announcements, release notes, etc.).
- Preferred method of communication for enquiries and updates, if required.
Reports can be written in German or English.
Download - PSIRT & Coordinated Vulnerability Disclosure (CVD) Policy of Maschinenfabrik Berthold HERMLE AG
PSIRT & CVD Policy of HERMLE AG
Publication of security advisories
Reports relating to vulnerabilities and security advisories are published by HERMLE in cooperation with CERT@VDE:
Display all publications VDE CERT
In case of any questions about the advisories
please contact HERMLE Service