Report a vulnerability

Please describe in your report as clearly as possible how the issue can be reproduced; this helps us resolve it quickly. In most cases, the IP address or URL of the affected system and a description of the vulnerability will suffice. For more complex vulnerabilities, additional information may be required. If you choose to leave your contact details, we will get in touch with you.

Please make sure that:

  • You report the vulnerability as soon as possible after discovering it.
  • You do not share information about the security issue with others until you hear from us or the issue has been resolved.
  • You handle knowledge of the security issue responsibly, for example by not performing any actions beyond what is necessary to demonstrate the vulnerability.

What should you avoid?

Always refrain from the following actions:

    • Installing malware
    • Copying, modifying, or deleting data from a system
    • Making changes to the system
    • Repeatedly accessing the system or sharing access with others
    • Using brute force to gain access to a system
    • Using denial-of-service attacks or social engineering techniques

Report a vulnerability

Describe the problem as much in detail as possible.  What is the impact? What systems are affected?

How did you get aware of the active exploitation?

Upload screenshots, logfiles, PCAP, PoC-code or reports that support the Proof of Concept.

Principles of Our Policy

We handle reports in accordance with ENISA’s good practice guidance and the statutory CRA frameworks.

  • Confirmation of receipt: Within three working days, you will receive confirmation of your report.
  • Validation & Updates: Our security team will assess the report. We aim to provide you with a status update on the progress of your report every 14 days.
  • Notification requirement:
    • Within 24 hours: After Intergas becomes aware of an actively exploited vulnerability or a serious incident, an first report will be submitted via the ENISA Single Reporting Platform.
    • Within 72 hours: After acknowledgement, a detailed report will be submitted to ENISA detailing the nature of the vulnerability, an initial assessment of its severity, and the corrective measures taken or planned.
    • Within 14 days: After the security update has been made available, Intergas will submit a final report to ENISA containing a full analysis, the affected products and definitive mitigation measures.