Vulnerability Handling and Disclosure Policy

POWER ELECTRONICS (PE) has established this policy to provide a clear and secure channel for reporting potential vulnerabilities in its products, and to set out its commitments regarding the handling and disclosure of such vulnerabilities, in compliance with Regulation (EU) 2024/2847 (Cyber Resilience Act) and (EU) 2022/2555 (NIS2).

This policy applies to products containing digital elements manufactured and sold by POWER ELECTRONICS (PE) and to the digital services operated as part of those products (Annex Product applied).

The following are expressly excluded from the scope of this policy:

  • The internal corporate infrastructure of POWER ELECTRONICS (PE).
  • External websites and applications not related to the product service.
  • Services operated by third parties, even if they are associated with POWER ELECTRONICS (PE).
  • Equipment that has reached the end of its life.

Power Electronics commits not to pursue civil legal action or request the initiation of criminal proceedings against any natural or legal person who reports vulnerabilities in accordance with this policy, provided that all conditions are met. Failure to comply with any of the conditions set out below shall automatically extinguish this protection.

  • The research is conducted in good faith, solely for the purpose of identifying cybersecurity vulnerabilities for remediation. Activities pursued for purposes of industrial espionage, obtaining competitive advantage, extortion, blackmail, or any purpose unrelated to improving product security are excluded;
  • The activity adheres to all applicable laws, including, without limitation, legislation on personal data protection, trade secrets, intellectual property, computer access, and network and information systems security;
  • The researcher employs only those methods strictly necessary to identify and verify the existence of the vulnerability, and ceases all exploitation activity immediately upon obtaining the minimum proof of concept sufficient to document it;
  • The testing does not compromise the safety of any person, the stability or availability of electrical grids or energy infrastructure, or the availability, integrity, or confidentiality of data, systems, or services belonging to customers, operators, or any third party; and
  • The researcher complies with all disclosure conditions set out below, including mandatory prior notification to Power Electronics and the applicable embargo period.

1. Report

To report vulnerabilities arising from the products specified in the defined product list, the following reporting channels have been established:

The report must contain the following information:

  • Affected product and firmware or software version.
  • Description of the vulnerability, and information on how to reproduce it (Proof of Concept, screenshots, logs, etc.).

The report may be sent encrypted using the PGP key published by Power Electronics.

2. Analysis and Handling

Reports received by POWER ELECTRONICS (PE) will be analyzed, and the vulnerability will undergo technical validation, including an assessment of its impact on confidentiality, integrity and availability of information, intellectual property and service continuity, as well as their exploitability and the operational context. If the vulnerability is confirmed to be genuine, a patch or mitigation measure will be developed.

3. Disclosure

A coordinated vulnerability disclosure will be issued in conjunction with the reporter, in accordance with the embargo period and disclosure conditions established in this policy. Affected customers and operators of installations where vulnerable products are deployed will be notified directly. The relevant security notice will be published on ENISA official website and, where applicable, through the CSIRT designated as coordinator. Once a security update or other remediation measure is available, Power Electronics will, in agreement with ENISA, contribute the resolved vulnerability to the European vulnerability database established pursuant to Article 12(2) of Directive (EU) 2022/2555. The vulnerability disclosure will contain the following information:

  • Description of vulnerability with CVE reference and CVSS score.
  • Affected products and software/hardware versions.
  • Mitigations and fixes.

Conditions Relating to Disclosure

Mandatory Prior Notification. The researcher shall report any discovered vulnerability to Power Electronics through the channels indicated in the Report section below before disclosing it to any third party, publishing it in any medium (including forums, social media, conferences, public repositories, or academic publications), or making it available to any person other than Power Electronics or a CSIRT designated as coordinator.

Manufacturer-Led Coordinated Disclosure. Power Electronics shall have the right to make the first public disclosure of any vulnerability reported under this policy during the applicable coordinated disclosure period. The researcher shall not publicly disclose any information relating to the vulnerability until the earlier of: (a) Power Electronics has published a security advisory or otherwise publicly disclosed the vulnerability; (b) Power Electronics has confirmed in writing that the vulnerability has been remediated and authorized coordinated disclosure; or (c) the applicable coordinated disclosure period has expired.

Embargo Period. The researcher shall refrain from publicly disclosing any information relating to the vulnerability for a minimum period of ninety (90) calendar days from confirmed receipt of the report by Power Electronics, unless Power Electronics authorizes early disclosure in writing. Power Electronics may request a reasonable extension of this period where the complexity of the fix, the need for coordination with installation operators, or the distribution of updates to equipment deployed in critical infrastructure requires.

Embargo Extension for Critical Infrastructure Risk. Where the reported vulnerability may affect the stability of electrical grids, the safety of energy storage installations, or the availability of electric vehicle charging infrastructure, and Power Electronics reasonably demonstrates that remediation requires coordination with grid operators, installation owners, or regulatory authorities, the embargo period shall be automatically extended by an additional thirty (30) calendar days, up to a maximum of one hundred and twenty (120) days from the initial report.

Scope of Permitted Disclosure. Once the embargo period has elapsed, the researcher may publicly disclose the general nature of the vulnerability and its potential impact, and confirmation that Power Electronics has been notified and, where applicable, that a security update has been released. The researcher shall not disclose: (a) functional exploit code, attack tools, or operational proofs of concept; (b) detailed technical information sufficient to reproduce the attack while deployed equipment has not yet received the security update; or (c) data, credentials, configurations, network architectures, or other information obtained during the research, except to the extent strictly necessary to describe the vulnerability in generic terms.

Confidentiality of Obtained Information. All technical information, data, configurations, credentials, cryptographic keys, or any other information obtained as a result of research activity shall be treated as confidential. The researcher shall securely and irreversibly delete all copies of such information once the vulnerability has been reported and its receipt confirmed by Power Electronics, unless strictly necessary to document the vulnerability report.