Eine Schwachstelle oder ein Sicherheitsproblem melden
Vulnerability Disclosure Policy
Introduction
Zumtobel Group is a provider of integrated lighting solutions for professional indoor and outdoor lighting and offers a comprehensive range of high-quality luminaires, lighting control systems and multi-purpose sensors for various professional lighting applications. The Zumtobel Group operates under several brands, including in particular Zumtobel, Thorn and Tridonic. In this policy, “Zumtobel” therefore refers to Zumtobel Group AG and its group companies and the products marketed under the brands of the Zumtobel Group (“Zumtobel Group”). As a manufacturer of technologically sophisticated control systems and software, security is also a core value of Zumtobel. Therefore, Zumtobel is committed to ensuring the security of users of Zumtobel products and software by protecting their privacy and data.
Zumtobel Group is a provider of integrated lighting solutions for professional indoor and outdoor lighting and offers a comprehensive range of high-quality luminaires, lighting control systems and multi-purpose sensors for various professional lighting applications. The Zumtobel Group operates under several brands, including in particular Zumtobel, Thorn and Tridonic. In this policy, “Zumtobel” therefore refers to Zumtobel Group AG and its group companies and the products marketed under the brands of the Zumtobel Group (“Zumtobel Group”). As a manufacturer of technologically sophisticated control systems and software, security is also a core value of Zumtobel. Therefore, Zumtobel is committed to ensuring the security of users of Zumtobel products and software by protecting their privacy and data.
Because Zumtobel values the contribution of external security researchers acting in good faith to help maintain a high standard of security and privacy for our users and systems, this policy is intended to provide security researchers with clear guidelines for conducting vulnerability disclosure activities and to communicate our preferences in reporting discovered vulnerabilities to us.
We strongly encourage security researchers, customers, partners and other stakeholders to report potential security vulnerabilities in Zumtobel products, firmware, software and related services. Coordinated Vulnerability Disclosure contributes to identifying and remediating vulnerabilities before they can be exploited and supports Zumtobel's vulnerability management and product security processes.
Authorization
If you make a good faith effort to comply with this policy during your security research, Zumtobel will treat your research as authorized and will work with you to understand and remediate the reported issue.
If you make a good faith effort to comply with this policy during your security research, Zumtobel will treat your research as authorized and will work with you to understand and remediate the reported issue.
Researchers must comply with all applicable laws and regulations and act in a manner that avoids harm to Zumtobel, its customers, users, partners and systems.
Zumtobel will not initiate civil claims or file criminal complaints against researchers for security research conducted in good faith and in accordance with this policy. Please note, however, that this commitment binds only Zumtobel: it cannot limit the rights of third parties or the powers of law enforcement and other public authorities under applicable law. If legal action is initiated by a third party against a researcher who has complied with this policy, Zumtobel will make this authorization known. This authorization and the commitments given in this policy apply only if and for as long as you comply with the rules set out in this policy and do not violate applicable data protection law; they do not apply where your activities interfere with the rights of third parties.
Scope
This policy applies to:
This policy applies to:
- Products of the brands of the Zumtobel Group (for example Zumtobel, Thorn and Tridonic)
- Associated firmware
- Product-related software
- Connected services, cloud services and web applications operated by or on behalf of Zumtobel
Submissions unrelated to vulnerabilities in Zumtobel products, firmware, software or related services may not be processed under this policy.
This policy covers only systems, products and services that Zumtobel is entitled to dispose of. Infrastructure operated by third parties (e.g. hosting or cloud providers) and accounts or data of other users are out of scope; testing such systems requires the prior consent of the respective third party. Only ever use your own accounts and test data.
Guidelines
Under this policy, "research" means activities in which you:
Under this policy, "research" means activities in which you:
- Notify us as soon as possible after discovering a real or potential security issue.
- Make every effort to avoid privacy violations, degradation of user experience, interruption of services, destruction of data or modification of information.
- Only use exploits to the extent necessary to confirm the existence of a vulnerability.
- Do not exfiltrate data, establish persistent access, create backdoors or pivot to other systems.
- Stop testing immediately if sensitive information is encountered and notify us without undue delay.
- Use test or demo environments where available.
- Coordinate any planned public disclosure with Zumtobel.
The following activities are not permitted: - Social engineering attacks.
- Physical attacks against facilities, personnel or assets.
- Denial-of-Service (DoS) or Distributed Denial-of-Service (DDoS) testing.
- Brute-force attacks or credential stuffing.
- Copying, modifying or deleting customer or company data.
- Repeated unauthorized access beyond what is necessary to validate a finding.
- Public disclosure before a coordinated remediation process has been agreed.
Handle personal data with strict data minimisation: if you encounter personal data (such as customer, employee or user data), immediately stop the activity concerned, do not access, copy, extract or store such data beyond what is strictly unavoidable to demonstrate the finding, do not include real personal data in screenshots, proof-of-concept material or reports, and delete any personal data obtained without undue delay after submission of your report.
Reporting a Vulnerability
We accept vulnerability reports via:
We accept vulnerability reports via:
For confidential submissions, reporters are encouraged to use encryption and provide sufficient contact details so that we can communicate throughout the remediation process. To support efficient assessment, remediation, regulatory reporting obligations and compliance with the Cyber Resilience Act (CRA), reporters are encouraged to provide all relevant information regarding the vulnerability, affected products, versions, potential impact, exploitation details and reproduction steps, as well as any additional information reasonably required for internal processing and, where applicable, reporting to ENISA or other competent authorities.
Reports may also be submitted anonymously. In addition, in accordance with Regulation (EU) 2024/2847 (Cyber Resilience Act, “CRA”) and Directive (EU) 2022/2555 (NIS 2), vulnerabilities may be reported – anonymously, if the reporter so wishes – indirectly via the CSIRT designated as coordinator for the purposes of coordinated vulnerability disclosure in the relevant Member State, which may act as an intermediary between the reporter and Zumtobel.
The CSIRT designated as coordinator for Austria is CERT.at (national CSIRT). Reports concerning Germany may also be submitted – anonymously, if desired – to the German Federal Office for Information Security (BSI). Anonymous reports are handled in the same way as any other report; status updates can, however, only be provided where a means of contact is given.
Any personal data provided with a report will be processed solely for the purpose of handling the report, coordinating remediation and complying with legal obligations, in accordance with applicable data protection law (GDPR). Further information is available in Zumtobel Brand’s privacy statement (see footer).
Zumtobel treats the identity of reporters confidentially and will not disclose it to third parties (including suppliers or component manufacturers) without the reporter’s consent, unless disclosure is required by law. Personal data of reporters is retained only for as long as necessary for handling the report and for compliance with statutory obligations, and is deleted thereafter.
Reporting Rules
To help us triage and prioritize submissions, we recommend that your report:
To help us triage and prioritize submissions, we recommend that your report:
- Is written in English, where possible.
- Contains a clear description of the vulnerability.
- Identifies the affected product and article number.
- Includes the manufacturing date (if applicable).
- Includes firmware, software and product version information.
- Describes the potential impact and exploitation scenario.
- Specifies the operating system and version used during testing.
- Includes browser type and version for web-based services.
- Provides relevant network configuration details where applicable.
- Includes the date and time of testing.
- Contains detailed reproduction steps.
- Includes screenshots, logs or proof-of-concept material if available.
- Identifies tools or test configurations used.
- Includes any available risk assessment, evidence of exploitation or CVSS information.
- Identifies any coordination with CERTs, CSIRTs, vulnerability coordinators or national authorities.
Information Sharing
Information submitted under this policy will be used for defensive purposes only, including:
Information submitted under this policy will be used for defensive purposes only, including:
- Vulnerability assessment
- Product security improvements
- Remediation activities
- Incident response
- Regulatory compliance obligations
If reported vulnerabilities affect third-party components, suppliers or service providers integrated into Zumtobel products, Zumtobel may share relevant information with those parties for remediation and coordinated vulnerability handling purposes.
Where a reported vulnerability is identified in a component integrated into a Zumtobel product with digital elements, including free and open-source components, Zumtobel will report the vulnerability to the person or entity manufacturing or maintaining that component in accordance with Article 13(6) CRA and, where Zumtobel has developed a modification to address the vulnerability, will share the relevant code or documentation with that person or entity.
What You Can Expect From Us
When you choose to share your contact information with us, we commit to coordinating with you as openly and as quickly as possible. To support this process, Zumtobel has established a dedicated Product Security and Incident Response Organization to manage vulnerability reports, coordinate remediation activities and fulfil applicable regulatory obligations.
When you choose to share your contact information with us, we commit to coordinating with you as openly and as quickly as possible. To support this process, Zumtobel has established a dedicated Product Security and Incident Response Organization to manage vulnerability reports, coordinate remediation activities and fulfil applicable regulatory obligations.
Zumtobel will:
- Acknowledge receipt of your report without undue delay, generally within five business days.
- Assign a tracking number where appropriate.
- Assess and validate the reported vulnerability.
- Coordinate remediation with affected product teams and suppliers.
- Provide a status update at least every 20 calendar days until closure or resolution.
- Inform you when remediation activities have been completed.
If the vulnerability affects a third-party component, we may coordinate with the responsible supplier and may refer relevant information to them to support remediation efforts.
Coordinated Vulnerability Disclosure
As part of responsible Coordinated Vulnerability Disclosure, Zumtobel encourages researchers to work with us when determining public disclosure timelines. To minimize risks to customers, users and other stakeholders, reporters should inform Zumtobel of any planned disclosure activities before publishing vulnerability details. Where appropriate, Zumtobel may publish security advisories, mitigation guidance or security update information once remediation measures are available. Researchers who submit valid reports may be acknowledged publicly, unless anonymity is requested.
As part of responsible Coordinated Vulnerability Disclosure, Zumtobel encourages researchers to work with us when determining public disclosure timelines. To minimize risks to customers, users and other stakeholders, reporters should inform Zumtobel of any planned disclosure activities before publishing vulnerability details. Where appropriate, Zumtobel may publish security advisories, mitigation guidance or security update information once remediation measures are available. Researchers who submit valid reports may be acknowledged publicly, unless anonymity is requested.
Once a security update addressing a reported vulnerability has been made available, Zumtobel will, in accordance with Annex I Part II point (4) CRA, share and publicly disclose information about the fixed vulnerability, including a description of the vulnerability, information allowing users to identify the product with digital elements affected, the impact and severity of the vulnerability, and clear and accessible information helping users to remediate it. In duly justified cases, where Zumtobel considers that the security risks of publication outweigh its benefits, the publication of such information may be deferred until users have been given the possibility to apply the relevant patch.
Cyber Resilience Act Compliance
Zumtobel operates a documented vulnerability handling process and aims to assess reported vulnerabilities without undue delay, taking their potential impact and regulatory reporting obligations into account to support applicable cybersecurity obligations, including those arising under the European Union Cyber Resilience Act (CRA).
Zumtobel operates a documented vulnerability handling process and aims to assess reported vulnerabilities without undue delay, taking their potential impact and regulatory reporting obligations into account to support applicable cybersecurity obligations, including those arising under the European Union Cyber Resilience Act (CRA).
Where Zumtobel becomes aware of an actively exploited vulnerability contained in one of its products with digital elements, or of a severe incident having an impact on the security of such a product, Zumtobel will notify the CSIRT designated as coordinator and ENISA within the timeframes laid down in Article 14 CRA (early warning within 24 hours, vulnerability or incident notification within 72 hours, and a final report within the prescribed periods) and will inform impacted users – and, where appropriate, all users – in accordance with Article 14(8) CRA. Reports submitted under this policy are assessed without undue delay to determine whether these notification obligations are triggered.
Reported vulnerabilities may be incorporated into:
- Vulnerability management activities
- Security risk assessments
- Corrective actions and security updates
- Supplier and third-party coordination processes
- Regulatory reporting obligations where applicable
- Product cybersecurity documentation and security maintenance processes
This policy is published on Zumtobel’s website. Zumtobel additionally intends to make the relevant reporting information available in machine-readable form (e.g. via a “security.txt” file in accordance with RFC 9116). The single point of contact for reporting vulnerabilities and information on where this policy can be found are also stated in the user information and instructions accompanying Zumtobel products, in accordance with Annex II point (2) CRA.