Security at Ollendorf Measurement Systems
- Handling Vulnerability Reports -
Report a Vulnerability
We welcome reports from independent security researchers, customers, partners, and others concerned with the security of our products.
- Product name and version that contains the vulnerability
- Type of vulnerability (e.g. code execution, denial of service, buffer overflow)
- Instructions to reproduce the vulnerability
- Proof-of-concept or exploit code
- Potential impact of the vulnerability, including how an attacker could exploit it
- Your contact details for follow-up questions
Coordinated Vulnerability Disclosure
We follow the principle of Coordinated Vulnerability Disclosure (CVD): anyone who discovers a vulnerability in our product reports
it directly to us and gives us the opportunity to investigate and remediate it before the information is disclosed publicly.
Remediation
- a new release
- a security update
- instructions to install a third-party update
- a workaround to mitigate the vulnerability
Notwithstanding the above, we do not guarantee a specific resolution or timeframe for every reported vulnerability.
Legal Notice
This page describes our current approach to handling security reports and may change at any time without notice. It does not create any entitlement to a specific response time, outcome, or compensation. Information provided to us as part of a vulnerability report becomes our sole property.