Abloy believes that the responsible disclosure of vulnerabilities is essential for improving the quality of our products and services, safety of our customers that rely on them, and awareness as to their choices relative to preserving their specific interests. Abloy values insight from the security research community and welcomes responsible disclosure and collaboration with this community.
Abloy values the insight and commitment of security researchers and other vulnerability investigators to make the world a safer place by discovering vulnerabilities of security solutions and providing mechanisms to privately report them with legitimacy and integrity.
Responsible disclosure program ensures that security access infrastructure is tested and proven reliable. Moreover, the commitment to mitigate vulnerabilities is reassuring for our customers and the security industry as a whole.
The following is Abloy’s responsible disclosure policy:
We ask the security researcher community to work with Abloy to coordinate the public disclosure of a vulnerability. Prematurely revealing a vulnerability publicly without first notifying Abloy could hurt end-users, exposing sensitive information and putting people and organizations in danger of malicious attacks.
To that end, Abloy strongly advocates a two-step process: first, private disclosure of a potential vulnerability to Abloy. Once the vulnerability is validated, resolved and Abloy and its customers provided a reasonable time to deploy fixes, Abloy coordinates the public disclosure, which includes the recognition of the security researcher’s discovery, confirming that credit is given to the right person(s).
We ask that researchers recognize that our action to investigate, validate and remediate reported vulnerabilities varies based on complexity and severity. We will communicate expected timelines, changes and collaborate where possible. Additionally, we request that researchers not utilize Denial of Service tools or compromise Abloy user infrastructure or personal; information while performing testing or evaluation.
Like other leading companies, Abloy applies industry best practices for coordinated disclosure of vulnerabilities to protect the security ecosystem, ensuring that customers get the highest quality information, drive public discourse about ways to improve products, protocols, methodologies, standards and solutions.
If you believe you have discovered a vulnerability, refer to the “Reporting Guidelines” link in the menu in this Abloy Product Security Center for instructions on how to contact the Abloy Product Security Response Team to report your finding privately.