This document describes the process of reporting and handling vulnerabilities for all Super B products.
Super B has a Product Security Incident Response Team (PSIRT) that is the central point of contact for external security researchers, partners, and customers to report cybersecurity information related to products developed by Super B and its brands.
The e-mail address to this response team is psirt@super-b.com
The website includes information regarding vulnerability reporting and handling at: super-b.com/psirt
The process includes the following steps:
Each of the sections are explained below:
A potential vulnerability is reported to the Super B PSIRT via psirt@super-b.com.
The Super B PSIRT cooperates with the relevant engineering team to investigate and reproduce the vulnerability. Super B performs internal vulnerability handling in collaboration with the responsible development groups.
After the issue is analysed, it is defined if a fix or mitigation is necessary to address the vulnerability. To the extent possible, the Super B PSIRT will work with the reporting party to verify and review fixes.
Corresponding fixes will be developed and prepared for distribution, passing through the quality controls as needed for the Super B product.
The Super B PSIRT in conjunction with the reporting party will create a disclosure schedule. If public disclosure of the vulnerability is agreed upon, the Super B PSIRT will release a Security Advisory at super-b.com/psirt in coordination with the reporting party's potential publication plans.
A security advisory usually contains the following information:
If the vulnerability has functional impact, the changes will also be included in the corresponding release notes for the product software/firmware release which include the fix for that vulnerability.
In addition to the internal handling process described above, Super B is required by the EU Cyber Resilience Act (CRA) to notify the relevant authorities when a vulnerability in one of its products is actively exploited.
The Super B PSIRT is responsible for assessing whether a vulnerability meets the notification threshold and for submitting the required notifications within the deadlines below.
A vulnerability triggers the mandatory notification obligation when it is actively exploited in the wild, meaning there is credible evidence that an attacker is using the vulnerability against real users or deployments of a Super B product.
Reported vulnerabilities that are not yet actively exploited are handled through the standard Triage, Remediation, Disclosure process and do not require regulatory notification unless exploitation is later confirmed.
Once active exploitation is confirmed, the Super B PSIRT must submit the following notifications to the European Union Agency for Cybersecurity (ENISA) via the designated national CSIRT or single reporting platform:
Early Warning
Vulnerability Notification
Final Report
If a final fix is not available within 14 days, an interim progress report should be submitted and the final report issued once the fix is ready.
Notifications are submitted to the national CSIRT of the EU member state where Super B is established. The designated reporting channel is coordinated through ENISA's single reporting platform as defined under CRA Article 16.
The Super B PSIRT is responsible for identifying the correct reporting channel at the time of notification and keeping contact details up to date.
The Super B PSIRT maintains an internal record of all regulatory notifications submitted, including timestamps, content, and any responses received. This record is retained for a minimum of 10 years in accordance with CRA Article 13(10).