Snom Technology GmbH ("Snom") is committed to maintaining the security of its products, services, and supporting infrastructure.
This Vulnerability Disclosure Policy (VDP), also referred to as a Coordinated Vulnerability Disclosure (CVD) Policy, explains how security researchers, customers, partners, and members of the public can responsibly report potential security vulnerabilities affecting Snom products and services.
Snom supports responsible security research and values reports that help improve the security and resilience of our products. We are committed to handling vulnerability reports in a transparent, consistent, and responsible manner and to protecting customers through appropriate remediation and communication processes.
This policy applies to potential vulnerabilities that may negatively impact:
of Snom products with digital elements, including:
The following are generally outside the scope of this policy:
Third-party vulnerabilities should be reported to the respective vendor.
Snom supports Coordinated Vulnerability Disclosure based on the following principles:
The Snom Product Security Incident Response Team (PSIRT) is responsible for managing product security vulnerabilities.
The PSIRT is responsible for:
Security vulnerabilities may be reported through the following channels:
The reporting channels above are intended exclusively for security-related reports.
To assist with investigation and remediation, please provide as much of the following information as possible:
Reports may be submitted anonymously; however, anonymity may limit our ability to investigate and provide status updates.
Researchers participating in responsible disclosure activities are expected to:
If security research is conducted in good faith and in accordance with this policy, Snom will consider such activities authorized.
Snom will not initiate legal action against individuals who:
If a third party initiates legal action relating to activities conducted in accordance with this policy, Snom may make it known that the activities were consistent with this policy.
Snom is committed to timely and transparent communication.
We aim to acknowledge receipt of vulnerability reports within five (5) business days.
We aim to provide an initial assessment or request additional information within ten (10) business days.
For validated vulnerabilities under investigation, we aim to provide periodic status updates throughout the remediation process.
Response times may vary depending on the complexity and severity of the issue.
Snom operates a structured vulnerability handling process that includes:
The vulnerability is evaluated to determine:
Severity may be assessed using industry-recognized methodologies such as CVSS.
When appropriate, Snom develops and tests:
Remediation measures are verified before public release.
Where appropriate, Snom publishes Security Advisories containing information regarding affected products, remediation measures, mitigations, and update availability.
Snom supports Coordinated Vulnerability Disclosure.
We request that researchers refrain from publicly disclosing vulnerabilities until:
Snom has investigated the issue;
Users have had a reasonable opportunity to deploy available mitigations or updates; or
A coordinated disclosure date has been agreed.
Snom reserves the right to disclose vulnerability information earlier where required to protect customers, address active exploitation, or comply with legal obligations.
Where appropriate, Snom publishes Security Advisories through its Security Center.
Security Advisories may include:
Snom provides security updates for supported products throughout their published security support period.
Current support periods are available in the Product Security Lifecycle section of the Security Center.
After a product reaches its published End of Security Support date, Snom may no longer provide security updates or remediation for newly discovered vulnerabilities.
Many Snom products incorporate third-party software components and open-source software.
When vulnerabilities affecting such components are identified, Snom assesses their impact on affected products and provides remediation, updates, or guidance where appropriate.
Where applicable, Snom fulfills regulatory reporting obligations concerning actively exploited vulnerabilities and security incidents in accordance with applicable legal requirements.
Such obligations may exist independently from the coordinated disclosure process described in this policy.
Snom treats vulnerability reports confidentially and processes personal information in accordance with applicable privacy and data protection laws.
Reporter information will not be disclosed outside Snom without consent unless required by law.
Snom does not currently operate a bug bounty program.
At Snom's discretion, researchers who responsibly disclose valid vulnerabilities may be acknowledged in public Security Advisories or other recognition programs, subject to their consent.
This policy may be reviewed and updated periodically to reflect changes in products, security practices, legal requirements, and industry standards.
The latest version will always be published through the Snom Security Center.
Contact Information:
Product Security Incident Response Team (PSIRT)
+49 30 - 39833-0
Office hours: Mo-Fr 9:00-17:00 (CET)
Sales DACH
+49 30 39833 0
website@snom.com
Please choose the regional Snom website you would like to visit.
For the United States, Canada, Central and South America:
For the Rest of the World: