Glossary · OT security engineering
Vulnerability disclosure
Also known as: Vulnerability reporting
German: Schwachstellenoffenlegung
In product security, vulnerability disclosure is the process of receiving reports about potential vulnerabilities in products or services and publishing information about confirmed vulnerabilities, their impact and their remediation to users. ISO/IEC 29147 gives requirements and recommendations for vendors.
- Security engineering
- OT security
- Standards
In one sentence
Vulnerability disclosure covers receiving reports of vulnerabilities and publishing information about confirmed ones and their remediation to users.
Example
A robot manufacturer lists a security contact and a PGP key on its website, receives a report about a controller service, and later publishes an advisory describing the fix.
Explained in context
Context cards connect this term with others to answer one question. Also in British English and German.
How it applies
- Product development: Vendors need a public, easy-to-find way to receive reports, for example a security contact page or a security.txt file on their website, and an internal process to triage them. ISO/IEC 30111 describes the internal vulnerability handling that follows.
- Compliance: The Cyber Resilience Act (CRA) requires manufacturers to provide a contact address for reporting vulnerabilities and to share information about fixed vulnerabilities with users.
- Operation: Operators and integrators who find vulnerabilities in supplier products should report them through these channels rather than publishing them.
- Documentation: Product documentation, type labels or packaging and the website should point to the vulnerability reporting contact. Published information should be precise about affected versions and remediation and use the same product names as the manuals.
Vulnerability disclosure vs. coordinated vulnerability disclosure
Vulnerability disclosure is the general process of reporting and publishing. Coordinated vulnerability disclosure (CVD) adds the coordination among reporter, vendor and other parties so that publication follows the availability of a fix or mitigation.