OLLENDORF MEASUREMENT SYSTEMS
 

Security at Ollendorf Measurement Systems 

- Handling Vulnerability Reports -


Ollendorf Measurement Systems aims to minimize the security risk to our customers through timely information, guidance, and remediation of vulnerabilities in our products. This is the responsibility of our Product Security Incident Response Team (PSIRT), which receives, investigates, internally coordinates, remediates, and, where appropriate, publishes information about reported vulnerabilities.



Report a Vulnerability

We welcome reports from independent security researchers, customers, partners, and others concerned with the security of our products.


Report a vulnerability now





To help us process your report, please include:


  • Product name and version that contains the vulnerability
  • Type of vulnerability (e.g. code execution, denial of service, buffer overflow)
  • Instructions to reproduce the vulnerability
  • Proof-of-concept or exploit code
  • Potential impact of the vulnerability, including how an attacker could exploit it
  • Your contact details for follow-up questions




Coordinated Vulnerability Disclosure

We follow the principle of Coordinated Vulnerability Disclosure (CVD): anyone who discovers a vulnerability in our product reports 

it directly to us and gives us the opportunity to investigate and remediate it before the information is disclosed publicly.


Our PSIRT stays in contact with the reporter throughout the investigation and provides regular progress updates. 
Once an update or mitigation has been published, the reporter is welcome to discuss the vulnerability publicly.


This approach protects our customers while allowing for coordinated disclosure.



Remediation

Remediation may take one or more of the following forms:


  • a new release
  • a security update
  • instructions to install a third-party update
  • a workaround to mitigate the vulnerability


Notwithstanding the above, we do not guarantee a specific resolution or timeframe for every reported vulnerability.



Legal Notice

This page describes our current approach to handling security reports and may change at any time without notice. It does not create any entitlement to a specific response time, outcome, or compensation. Information provided to us as part of a vulnerability report becomes our sole property.