Coordinated Vulnerability Disclosure (CVD) Policy

To maintain and improve the safety of the products and services we provide and to ensure information security for our customers and society, our corporate group (hereinafter "our company") has established this Coordinated Vulnerability Disclosure (CVD) Policy. Under our product security response framework, we are committed to receiving, evaluating, mitigating, and appropriately disclosing vulnerability information.

Purpose and Scope of the Policy

Under our product security response framework, we receive, evaluate, handle, and disclose vulnerabilities. This policy applies to vulnerability reports concerning products provided by our company. Specific details such as the scope of support, support period, and conditions for security updates are governed by the individual product documentation or separate advisories published by Fuji Electric. For products subject to the CRA, the support period will be determined and communicated in accordance with the applicable legal requirements, and security updates will be made available in accordance with those requirements. Please note that this policy generally does not cover vulnerabilities inherent solely to third-party products, non-security-related defects, quality issues, specification queries, or standard technical support requests.

Vulnerability Reporting Contact

We accept vulnerability reports via the following method:
Email
 Contact address: fe-psirt@fujielectric.com

Vulnerability Handling Process

We will evaluate reported vulnerabilities without undue delay and, as necessary, provide fixes or workarounds, and disclose information. Security updates will be made available and disseminated without undue delay and, where required by applicable law, free of charge. If disclosure increases the risk of exploitation and may compromise user safety, we may adjust or postpone the timing of disclosure to ensure users have the opportunity to take necessary countermeasures.

Communication with Reporters

Upon receiving a vulnerability report, we will carry out the following:

  • Send an acknowledgment of receipt.

  • Maintain continuous communication according to the progress of the investigation and response.

  • Share verification results or response policies.

  • Notify you of the final resolution and express our appreciation for your contribution.

Advisory Disclosure and Coordination with Relevant Organizations
Advisory Disclosure:

We will publish vulnerability advisories as necessary. Advisories will include an overview of the vulnerability, affected products, mitigation methods, and related information.

Coordination with Relevant Organizations:

Depending on the nature of the vulnerability, we may notify or share information with the provider of the affected component or appropriate relevant organizations such as JPCERT/CC in a timely manner. We may also notify domestic and international regulatory authorities as necessary based on laws and regulations. Where notification to domestic or international regulatory authorities is required by applicable law, we will make such notification within the prescribed time limits and through the prescribed reporting channels. In particular, for products with digital elements subject to the CRA, we will notify actively exploited vulnerabilities and severe incidents having an impact on the security of such products in accordance with Article 14 of the CRA through the Single Reporting Platform, including the required early warning, notification, and final report within the applicable statutory time limits.

Requests for Vulnerability Reporting
Requested Information:

Whenever possible, please include the affected product details (name, model number, version), a detailed description of the vulnerability, step-by-step reproduction instructions, and any relevant logs or documentation.

Post-report response:

After receiving your report, we will contact you. Please ensure your settings allow for contact via email and phone. As a general rule, we will send an acknowledgment of receipt within 7 days of receiving a vulnerability report. Depending on our company holidays (such as summer and year-end/New Year holidays) and the content of your report, it may take some time to send the acknowledgment of receipt. This external acknowledgment period does not affect any shorter internal escalation, assessment, user-information, or regulatory reporting deadlines required under applicable law.

Privacy Policy:

The vulnerability information and personal information you submit will be handled in accordance with the "Fuji Electric Co., Ltd. Privacy Policy | Fuji Electric".

Requests to reporters:

Please do not disclose vulnerability information to third parties until coordination with our company and relevant parties is complete. Also, when verifying vulnerabilities, please cooperate to avoid causing damage to our company or third parties.

Safe Harbor:

Fuji Electric considers activities conducted consistently with this policy to constitute "good faith" research. We will not initiate legal action against researchers who discover and report vulnerabilities in accordance with this CVD Policy.

Policy Review

We will review this policy as appropriate in response to changes in laws, standards, threat landscapes, and technologies.

Contact Us