Product Security

We are committed to continuously improve the safety of our products and protect your data. We believe it is essential to communicate openly and transparently about the measures we have taken to ensure data protection and information security. On this webpage, you will find the latest information and contact details regarding product safety.

Product Security Incident Reporting

The Product Security Incident Response Team (PSIRT) at Gema Switzerland GmbH is the central point of contact for reporting potential security vulnerabilities, incidents, and other security issues related to products, solutions, and services of Gema Switzerland GmbH. Please submit reports to the following address: 
psirt(at)gema.eu.com

We guarantee complete confidentiality when you submit reports to us. No confidentiality agreement is required to collaborate with us on the disclosure of security vulnerabilities. Gema Switzerland GmbH is not currently participating in a bug bounty program.

We can process reports most effectively if you provide us with the information listed below:

  • Name of the person reporting: (If you wish to remain anonymous, we will of course respect your request.) Otherwise: Email address and phone number where we can reach you. Affiliation: What is your organizational affiliation (if any)?
  • Type of security vulnerability reported: How would you describe the type of security vulnerability (e.g., XSS, buffer overflow, hard-coded credentials, etc.)?
  • Cause of the security vulnerability: Can you provide a code that demonstrates how the vulnerability can be triggered (proof-of-concept, PoC)? Alternatively, you can submit network traces (e.g., pcaps) or a description of how to reproduce the vulnerability.
  • Impact of the security vulnerability: Have you observed any effects resulting from or caused by the security vulnerability?
  • Affected components: In which products, solutions, or services did you find the security vulnerability? Please include all the information you have, such as the product family and group, and the firmware or software version. For services, please specify the relevant location (e.g., URL).
  • Confidentiality of the security vulnerability: Has the security vulnerability already been disclosed, or do you have specific plans to disclose it?

 


The Gema Switzerland GmbH PSIRT will acknowledge receipt of your report within three business days. We would like to thank all reporters in advance for their contributions. Your support helps us improve the security situation for Gema Switzerland GmbH and our customers.

Loading...