Výber regiónu Dynapac

More languages and regions to be announced soon!

Cybersecurity

Coordinated Vulnerability Disclosure Policy

Dynapac welcomes reports of potential security vulnerabilities that may affect its supported products with digital elements, related digital services, or Dynapac-operated digital platforms.

Scope

This policy applies to supported Dynapac products with digital elements, related digital services, and Dynapac-operated digital platforms. If you are uncertain whether an issue is in scope, you may still report it and Dynapac will assess it.

The following are generally not considered reportable vulnerabilities unless they create a demonstrable security risk:

• Defects that do not affect the availability, integrity, or confidentiality of data.
• Cross-site scripting on a static website or on a website that does not process sensitive user data.
​• Exposure of technical information, such as software versions, IP addresses, or usernames, unless it can be directly exploited.
• Missing HTTP security headers, including Cross-Origin Resource Sharing (CORS) controls, unless their absence results in a demonstrable security issue.
​• Low-impact issues without a realistic exploitation scenario, including issues that disclose only non-sensitive information or depend on phishing or extensive user interaction.

How to report a vulnerability

Submit reports through the designated reporting portal. Registration is required. The portal provides a secure communication channel for confidential vulnerability information.

Where available, include:

• the affected product or service and software version;
• a description of the vulnerability and its potential impact;
​• the steps required to reproduce the vulnerability; and
​• an email address that can receive replies.

What happens after submission

Dynapac's Product Security Incident Response Team (PSIRT) manages vulnerability reports. Each report is assigned a unique case reference and is acknowledged, assessed, validated, remediated, tested, and coordinated for disclosure as appropriate.

Dynapac will confirm receipt within two working days and provide an initial assessment within four working days. Progress updates will be provided during remediation where appropriate.

Reporter responsibilities

Please report the issue as soon as possible and limit your actions to those necessary to demonstrate it. Do not disclose the vulnerability to others until Dynapac confirms that it has been resolved or agrees to coordinated disclosure.

When researching or reporting a vulnerability, do not:

• introduce malware;
• copy, modify, or delete data;
​• make unnecessary changes to a system;
​• repeatedly access a system or share access with others;
​• perform brute-force attacks;
• perform denial-of-service attacks; or
• use social engineering.

Confidentiality and coordinated disclosure

If you act in good faith and comply with this policy, Dynapac will not pursue legal action in relation to your report. Dynapac will handle your report confidentially and will not share your personal information with third parties unless required by law or a court order.

Dynapac will identify you as the reporter only with your permission. After resolution, Dynapac will coordinate with you, where appropriate, regarding whether and how information about the vulnerability and its resolution will be disclosed.