Policy zur koordinierten Offenlegung von Schwachstellen / Coordinated Vulnerability Disclosure Policy
Warum diese Policy
Software enthält Fehler, auch sicherheitsrelevante. Wir wollen davon erfahren, bevor es jemand ausnutzt. Diese Policy beschreibt, wie Sie Schwachstellen in unseren Produkten melden, was Sie von uns erwarten können und wie wir gemeinsam den Zeitpunkt der Veröffentlichung festlegen. Sie erfüllt damit die Anforderung an eine Politik zur koordinierten Offenlegung nach Anhang I Teil II Nr. 5 der Verordnung (EU) 2024/2847 (Cyber Resilience Act) und orientiert sich an ISO/IEC 29147 und ISO/IEC 30111.
Für wen und was sie gilt
Die Policy gilt für alle Personen und Organisationen, die eine Schwachstelle in einem Produkt der CPS-Familie melden – Sicherheitsforschende, Kunden, Partner, Behörden und Hersteller von Vorprodukten. Sie umfasst die von uns ausgelieferten Anwendungen, Dienste und Weboberflächen sowie die darin enthaltenen Fremdkomponenten. Nicht umfasst sind von Kunden betriebene Infrastruktur, Fremdprodukte in Kundenverantwortung und Hardware Dritter; solche Meldungen leiten wir an die zuständige Stelle weiter und informieren Sie darüber.
Meldeweg
security@csg-systems.de — Deutsch und Englisch sind gleichwertig. Wenn Sie verschlüsselt melden möchten, schreiben Sie uns kurz, dann vereinbaren wir einen Weg. Der Eingang wird montags bis freitags von 8 bis 17 Uhr überwacht. Betrifft Ihre Meldung eine Schwachstelle, die bereits ausgenutzt wird, rufen Sie uns bitte zusätzlich an: 0800 999 77 80 (kostenfrei innerhalb Deutschlands) oder +49 4101 5150-351 (auch aus dem Ausland erreichbar), Montag bis Freitag, 8 bis 17 Uhr. Außerhalb dieser Zeiten stellen Sie bitte AKTIV AUSGENUTZT in den Betreff Ihrer E-Mail — das löst eine Benachrichtigung außerhalb der Bürozeiten aus.
Hilfreich sind: betroffenes Modul und Version, Beschreibung und Auswirkung, Reproduktionsschritte, Ihre Einschätzung zur Ausnutzbarkeit sowie die Angabe, ob und wie Sie genannt werden möchten.
Was wir zusagen
| Zusage | Frist |
|---|---|
| Empfangsbestätigung durch eine Person, nicht durch einen Autoresponder | 3 Arbeitstage |
| Erste Bewertung: bestätigt / nicht bestätigt / weitere Informationen nötig, mit Einstufung | 10 Arbeitstage |
| Statusmeldung, solange der Fall offen ist | alle 14 Tage |
| Behebung kritisch (CVSS ≥ 9,0) | 14 Tage |
| Behebung hoch (CVSS 7,0–8,9) | 30 Tage |
| Behebung mittel (CVSS 4,0–6,9) | 90 Tage |
| Behebung niedrig (CVSS < 4,0) | mit dem nächsten planmäßigen Release |
| Advisory veröffentlicht | mit dem Fix, spätestens 5 Arbeitstage danach |
Die Fristen für Empfangsbestätigung, Erstbewertung und Advisory laufen in Arbeitstagen ab Ihrer Meldung; Arbeitstage sind Montag bis Freitag, ausgenommen gesetzliche Feiertage in Schleswig-Holstein (Sitz der CSG Systems GmbH: Pinneberg). Die Behebungsfristen laufen in Kalendertagen ab dem Tag, an dem wir die Schwachstelle bestätigt haben — also ab der Erstbewertung, nicht ab Ihrer Meldung. Die Statusmeldung alle 14 Tage rechnet ebenfalls in Kalendertagen.
Maßstab ist die CVSS-Basisnote nach Version 3.1; im Advisory nennen wir immer den Vektor, damit die Note nachvollziehbar ist. Maßgeblich für die Frist ist die Stufe, nicht allein die Zahl: Wir bewerten zusätzlich, wie die Schwachstelle im CPS-Umfeld erreichbar ist — ein unbeaufsichtigter Automat oder eine offene Weboberfläche wiegt schwerer als ein Werkzeug, das Administratorrechte voraussetzt. Das kann die Stufe um eine Stufe heben oder senken. Weicht unsere Einstufung von Ihrer ab, sagen wir Ihnen, warum.
Wir nennen Sie im Advisory, wenn Sie das möchten. Und wir sagen Ihnen offen, wenn wir eine Frist nicht halten können, samt Begründung und neuem Termin.
Was wir von Ihnen erbitten
- Geben Sie uns Zeit zur Behebung: Standard-Embargo sind 90 Tage ab Ihrer Meldung. Wenn es länger dauert, sprechen wir mit Ihnen über eine Verlängerung; wir setzen sie nicht einseitig. Das Embargo betrifft ausschließlich die öffentliche Veröffentlichung — es verzögert weder die Information betroffener Kunden noch gesetzliche Meldepflichten.
- Testen Sie nur auf Systemen, für die Sie autorisiert sind – nicht in Produktivinstallationen unserer Kunden.
- Keine Denial-of-Service-Tests, kein Social Engineering, kein physischer Zugriff auf Kundenanlagen.
- Greifen Sie nicht mehr Daten ab als für den Nachweis nötig. Falls Sie unbeabsichtigt personenbezogene oder Zahlungsdaten sehen: Zugriff abbrechen, uns informieren, Daten nicht speichern oder weitergeben.
- Behandeln Sie die Meldung vertraulich, bis das Embargo endet oder wir gemeinsam etwas anderes vereinbaren.
Bei niedriger Einstufung kann der Fix hinter das Ende des Embargos fallen, weil er mit dem nächsten planmäßigen Release kommt. Dann stimmen wir den Veröffentlichungszeitpunkt mit Ihnen ab — unbefristete Verschwiegenheit erwarten wir nicht.
Safe Harbor
Wer sich an diese Policy hält, hat von uns keine rechtlichen Schritte zu erwarten – wir betrachten solche Forschung als autorisiert und gutgläubig. Wir werden Sie auch nicht bei Dritten anzeigen.
Diese Zusage bindet allerdings nur uns. Ansprüche Dritter kann sie nicht ausschließen – etwa von Kunden, deren Anlagen ohne Erlaubnis getestet wurden –, und ein Ermittlungsverfahren nach §§ 202a bis 202c StGB kann eine Staatsanwaltschaft auch ohne unser Zutun einleiten; darauf haben wir keinen Einfluss. Der Schutz entfällt bei Erpressung, Datenabfluss oder absichtlicher Beeinträchtigung.
Veröffentlichung
Zu jeder behobenen Schwachstelle veröffentlichen wir ein Advisory mit Beschreibung, betroffenen Versionen, Auswirkung, Schweregrad und Handlungsanweisung für Betreiber – so, dass Kunden entscheiden können, wie dringend sie einspielen müssen. Wir vergeben oder beantragen CVE-Nummern, wo das sinnvoll ist. Bei Schwachstellen, die Kunden aktiv gefährden, informieren wir betroffene Kunden direkt und ohne unnötige Verzögerung, unabhängig vom Embargo.
Fremdkomponenten
Betrifft eine Meldung eine Komponente eines Vorlieferanten, geben wir sie an dessen Hersteller weiter und koordinieren die Veröffentlichung mit ihm. Sie erfahren, an wen wir weitergegeben haben. Umgekehrt melden wir Erkenntnisse aus unserer eigenen Analyse an die Hersteller der von uns eingesetzten Komponenten.
Keine Prämien
Wir betreiben kein Bug-Bounty-Programm. Was wir bieten, ist eine verbindliche Antwort, eine ordentliche Behebung und – auf Wunsch – die Nennung Ihres Namens.
Änderungen
Welche Produkte und Versionen wie lange Sicherheitsupdates erhalten und wie diese bereitgestellt werden, regelt unsere Support- und Lebenszyklus-Erklärung. Sie wird gesondert veröffentlicht; bis dahin trifft diese Policy dazu keine Aussage.
Diese Policy wird jährlich überprüft. Die jeweils gültige Fassung steht unter https://www.csg-systems.de/security/disclosure-policy. Verantwortlich: Dr. Andreas Pfeiffer, Geschäftsführer, CSG Systems GmbH.
CSG Systems GmbH · CPS product family · Version 1.0 · 9 September 2026 · Next review: 9 September 2027
Why this policy exists
Software has flaws, including security-relevant ones. We would rather hear about them from you than from an attacker. This policy explains how to report a vulnerability in our products, what you can expect from us, and how we agree on the timing of publication. It implements the coordinated disclosure policy required by Annex I Part II (5) of Regulation (EU) 2024/2847 (Cyber Resilience Act) and follows ISO/IEC 29147 and ISO/IEC 30111.
Who and what it covers
This policy applies to anyone reporting a vulnerability in a CPS product — security researchers, customers, partners, authorities, and suppliers. It covers the applications, services, and web interfaces we ship, including the third-party components contained in them. It does not cover customer-operated infrastructure, third-party products under customer control, or third-party hardware; we forward such reports to the responsible party and tell you where they went.
How to report
security@csg-systems.de — English and German are equally welcome. If you would like to report encrypted, drop us a short note and we will agree on a channel. The mailbox is monitored Monday to Friday, 08:00–17:00 (Europe/Berlin). If your report concerns a vulnerability that is already being exploited, please also call +49 4101 5150-351 (reachable from outside Germany) or, within Germany, the toll-free number 0800 999 77 80 — Monday to Friday, 08:00–17:00 Europe/Berlin. Outside office hours, put ACTIVELY EXPLOITED in the subject line of your email — this triggers an out-of-hours notification.
Useful contents: affected module and version, description and impact, reproduction steps, your assessment of exploitability, and whether you would like to be credited.
What we commit to
| Commitment | Deadline |
|---|---|
| Acknowledgement by a person, not an autoresponder | 3 business days |
| Initial assessment (confirmed / not confirmed / more information needed) with severity | 10 business days |
| Status update while the case is open | every 14 days |
| Fix for critical issues (CVSS ≥ 9.0) | 14 days |
| Fix for high issues (CVSS 7.0–8.9) | 30 days |
| Fix for medium issues (CVSS 4.0–6.9) | 90 days |
| Fix for low issues (CVSS < 4.0) | with the next scheduled release |
| Advisory published | with the fix, at the latest 5 business days after |
The deadlines for acknowledgement, initial assessment and advisory run in business days from your report; business days means Monday to Friday, excluding public holidays in Schleswig-Holstein, Germany (our registered office is in Pinneberg). Fix deadlines run in calendar days from the day we confirmed the vulnerability — that is, from the initial assessment, not from your report. The 14-day status update is in calendar days as well.
The yardstick is the CVSS base score, version 3.1; every advisory states the vector so the score can be checked. What governs the deadline is the severity level, not the number alone: we also assess how the vulnerability can be reached in a CPS environment — an unattended machine or an exposed web interface weighs more than a tool that requires administrator rights. This can move the level up or down by one. Where our rating differs from yours, we tell you why.
We credit you in the advisory if you want us to. And we tell you openly when we cannot meet a deadline, with the reason and a new date.
What we ask of you
- Give us time to fix: the default embargo is 90 days from your report. If we need longer, we will discuss an extension with you rather than declaring one. The embargo concerns public disclosure only — it never delays informing affected customers or statutory reporting duties.
- Test only on systems you are authorised to test — never on our customers‘ production installations.
- No denial-of-service testing, no social engineering, no physical access to customer equipment.
- Access no more data than needed to demonstrate the issue. If you unintentionally encounter personal or payment data: stop, tell us, and do not store or share it.
- Keep the report confidential until the embargo ends or we agree otherwise.
For low-severity issues the fix may fall after the embargo ends, because it ships with the next scheduled release. In that case we agree the publication date with you — we do not expect open-ended silence.
Safe harbour
If you follow this policy, we will not take legal action against you — we consider such research authorised and in good faith, and we will not report you to third parties.
This assurance binds us only. It cannot waive the claims of third parties — for example customers whose installations were tested without permission — and criminal proceedings under sections 202a to 202c of the German Criminal Code can be initiated by a public prosecutor without any involvement on our part, which is outside our control. The protection does not apply in cases of extortion, data exfiltration, or deliberate disruption.
Publication
For every fixed vulnerability we publish an advisory with description, affected versions, impact, severity, and guidance for operators — enough for customers to judge how urgently they must deploy. We assign or request CVE identifiers where useful. Where a vulnerability actively endangers customers, we notify affected customers directly and without undue delay, regardless of the embargo.
Third-party components
If a report concerns a supplier’s component, we pass it on to that vendor and coordinate publication with them, and we tell you where it went. Conversely, we report findings from our own analysis to the vendors of the components we use.
No bounties
We do not run a bug bounty programme. What we offer is a binding response, a proper fix, and credit if you want it.
Changes
Which products and versions receive security updates for how long, and how those updates are made available, is set out in our support and lifecycle statement. That statement is published separately; until then, this policy makes no statement on it.
This policy is reviewed annually. The current version is published at https://www.csg-systems.de/security/disclosure-policy. Owner: Dr. Andreas Pfeiffer, Managing Director, CSG Systems GmbH.