Something new is coming Revealed at Caravan Salon Düsseldorf, 28 Aug–6 Sep More information

Product Security Incident Response Team (PSIRT)

This document describes the process of reporting and handling vulnerabilities for all Super B products.

Super B has a Product Security Incident Response Team (PSIRT) that is the central point of contact for external security researchers, partners, and customers to report cybersecurity information related to products developed by Super B and its brands.

The e-mail address to this response team is psirt@super-b.com

Website

The website includes information regarding vulnerability reporting and handling at: super-b.com/psirt

Vulnerability Reporting and Handling Process

The process includes the following steps:

  1. Vulnerability discovery
  2. Triage
  3. Remediation
  4. Disclosure

Each of the sections are explained below:

Discovery

A potential vulnerability is reported to the Super B PSIRT via psirt@super-b.com.

Triage

The Super B PSIRT cooperates with the relevant engineering team to investigate and reproduce the vulnerability. Super B performs internal vulnerability handling in collaboration with the responsible development groups.

Remediation

After the issue is analysed, it is defined if a fix or mitigation is necessary to address the vulnerability. To the extent possible, the Super B PSIRT will work with the reporting party to verify and review fixes.

Corresponding fixes will be developed and prepared for distribution, passing through the quality controls as needed for the Super B product.

Disclosure

The Super B PSIRT in conjunction with the reporting party will create a disclosure schedule. If public disclosure of the vulnerability is agreed upon, the Super B PSIRT will release a Security Advisory at super-b.com/psirt in coordination with the reporting party's potential publication plans.

A security advisory usually contains the following information:

  • Description of the vulnerability with CVE reference and CVSS score
  • Identity of known affected products and software/hardware versions
  • Information on mitigating factors and workarounds
  • Timeline and the location of available fixes or other remedial measures
  • With the reporting party's consent, recognition will be provided for reporting and collaboration.

If the vulnerability has functional impact, the changes will also be included in the corresponding release notes for the product software/firmware release which include the fix for that vulnerability.

Regulatory Notification Obligations (EU Cyber Resilience Act, Article 14)

In addition to the internal handling process described above, Super B is required by the EU Cyber Resilience Act (CRA) to notify the relevant authorities when a vulnerability in one of its products is actively exploited.

The Super B PSIRT is responsible for assessing whether a vulnerability meets the notification threshold and for submitting the required notifications within the deadlines below.

Notification Threshold

A vulnerability triggers the mandatory notification obligation when it is actively exploited in the wild, meaning there is credible evidence that an attacker is using the vulnerability against real users or deployments of a Super B product.

Reported vulnerabilities that are not yet actively exploited are handled through the standard Triage, Remediation, Disclosure process and do not require regulatory notification unless exploitation is later confirmed.

Notification Deadlines and Content

Once active exploitation is confirmed, the Super B PSIRT must submit the following notifications to the European Union Agency for Cybersecurity (ENISA) via the designated national CSIRT or single reporting platform:

Early Warning

  • Deadline: within 24 hours of becoming aware of active exploitation
  • Content: notification that an actively exploited vulnerability exists. Includes the affected product or products, the nature of the vulnerability at a high level, and whether a fix or workaround is available.

Vulnerability Notification

  • Deadline: within 72 hours of becoming aware of active exploitation
  • Content: updated notification including the severity assessment (CVSS score where available), known impact and affected versions, any interim mitigations or workarounds, and the status of the fix.

Final Report

  • Deadline: within 14 days of a fix or mitigation being available
  • Content: full report including a detailed description and CVE reference, root cause analysis, the full list of affected products and versions, the fix or mitigation applied, and a timeline of events.

If a final fix is not available within 14 days, an interim progress report should be submitted and the final report issued once the fix is ready.

National CSIRT and Reporting Channel

Notifications are submitted to the national CSIRT of the EU member state where Super B is established. The designated reporting channel is coordinated through ENISA's single reporting platform as defined under CRA Article 16.

The Super B PSIRT is responsible for identifying the correct reporting channel at the time of notification and keeping contact details up to date.

Record-Keeping

The Super B PSIRT maintains an internal record of all regulatory notifications submitted, including timestamps, content, and any responses received. This record is retained for a minimum of 10 years in accordance with CRA Article 13(10).

Contact

psirt@super-b.com