Coordinated Vulnerability Disclosure (CVD) Policy
To maintain and improve the safety of the products and services we provide and to ensure information security for our customers and society, our corporate group (hereinafter "our company") has established this Coordinated Vulnerability Disclosure (CVD) Policy. Under our product security response framework, we are committed to receiving, evaluating, mitigating, and appropriately disclosing vulnerability information.
Under our product security response framework, we receive, evaluate, handle, and disclose vulnerabilities. This policy applies to vulnerability reports concerning products provided by our company. Specific details such as the scope of support, support period, and conditions for security updates are governed by the individual product documentation or separate advisories published by Fuji Electric. For products subject to the CRA, the support period will be determined and communicated in accordance with the applicable legal requirements, and security updates will be made available in accordance with those requirements. Please note that this policy generally does not cover vulnerabilities inherent solely to third-party products, non-security-related defects, quality issues, specification queries, or standard technical support requests.
We accept vulnerability reports via the following method:
・Email
Contact address: fe-psirt@fujielectric.com
We will evaluate reported vulnerabilities without undue delay and, as necessary, provide fixes or workarounds, and disclose information. Security updates will be made available and disseminated without undue delay and, where required by applicable law, free of charge. If disclosure increases the risk of exploitation and may compromise user safety, we may adjust or postpone the timing of disclosure to ensure users have the opportunity to take necessary countermeasures.
Upon receiving a vulnerability report, we will carry out the following:
-
Send an acknowledgment of receipt.
-
Maintain continuous communication according to the progress of the investigation and response.
-
Share verification results or response policies.
-
Notify you of the final resolution and express our appreciation for your contribution.
We will publish vulnerability advisories as necessary. Advisories will include an overview of the vulnerability, affected products, mitigation methods, and related information.
Depending on the nature of the vulnerability, we may notify or share information with the provider of the affected component or appropriate relevant organizations such as JPCERT/CC in a timely manner. We may also notify domestic and international regulatory authorities as necessary based on laws and regulations. Where notification to domestic or international regulatory authorities is required by applicable law, we will make such notification within the prescribed time limits and through the prescribed reporting channels. In particular, for products with digital elements subject to the CRA, we will notify actively exploited vulnerabilities and severe incidents having an impact on the security of such products in accordance with Article 14 of the CRA through the Single Reporting Platform, including the required early warning, notification, and final report within the applicable statutory time limits.
Whenever possible, please include the affected product details (name, model number, version), a detailed description of the vulnerability, step-by-step reproduction instructions, and any relevant logs or documentation.
After receiving your report, we will contact you. Please ensure your settings allow for contact via email and phone. As a general rule, we will send an acknowledgment of receipt within 7 days of receiving a vulnerability report. Depending on our company holidays (such as summer and year-end/New Year holidays) and the content of your report, it may take some time to send the acknowledgment of receipt. This external acknowledgment period does not affect any shorter internal escalation, assessment, user-information, or regulatory reporting deadlines required under applicable law.
The vulnerability information and personal information you submit will be handled in accordance with the "Fuji Electric Co., Ltd. Privacy Policy | Fuji Electric".
Please do not disclose vulnerability information to third parties until coordination with our company and relevant parties is complete. Also, when verifying vulnerabilities, please cooperate to avoid causing damage to our company or third parties.
Fuji Electric considers activities conducted consistently with this policy to constitute "good faith" research. We will not initiate legal action against researchers who discover and report vulnerabilities in accordance with this CVD Policy.
We will review this policy as appropriate in response to changes in laws, standards, threat landscapes, and technologies.