Commend worldwide

Change your location

  • Commend Benelux荷兰、比利时
  • English
  • Commend Austria & CEE奥地利和中东欧 (CEE)
  • English
  • Commend Adria克罗地亚、波斯尼亚和黑塞哥维那、塞尔维亚
  • English
  • Commend Slovakia斯洛伐克、捷克
  • English
  • Commend Nordic丹麦、芬兰、冰岛、挪威、瑞典
  • English
  • Commend Nordic丹麦、芬兰、冰岛、挪威、瑞典
  • English
  • Commend Nordics丹麦、芬兰、冰岛、挪威、瑞典
  • English
  • Commend Benelux荷兰、比利时
  • English
  • Commend Nordic丹麦、芬兰、冰岛、挪威、瑞典
  • English
  • C&C Partners波兰、爱沙尼亚、拉脱维亚、立陶宛
  • English
  • Commend Ibèrica西班牙、葡萄牙
  • Spanish
  • Commend Austria & CEE奥地利和中东欧 (CEE)
  • English
  • Commend Slovakia斯洛伐克、捷克
  • English
  • Commend Austria & CEE奥地利和中东欧 (CEE)
  • English
  • Commend Ibèrica西班牙、葡萄牙
  • Spanish
  • Commend Nordic丹麦、芬兰、冰岛、挪威、瑞典
  • English
  • EFB Elektronik Türkiye土耳其
  • English
  • Commend Austria & CEE奥地利和中东欧 (CEE)
  • English
  • Commend Middle East阿联酋、黎凡特、海湾合作委员会
  • English
  • Commend Middle East沙特阿拉伯、黎凡特、阿联酋
  • English
  • Commend Middle East阿联酋、黎凡特、海湾合作委员会
  • English
  • Commend InternationalGlobal Website
  • English
  • Evolving Management Solutions (PTY)South Africa
  • English
  • TKHSAA印度尼西亚、马来西亚、菲律宾、新加坡、韩国、台湾、泰国
  • English
  • Commend Australia澳大利亚、新西兰
  • English
  • Commend Middle Asia哈萨克斯坦、吉尔吉斯斯坦、塔吉克斯坦、土库曼斯坦和乌兹别克斯坦
  • English
  • Russian
  • Commend Australia澳大利亚、新西兰
  • English
  • TKHSAA印度尼西亚、马来西亚、菲律宾、新加坡、韩国、台湾、泰国
  • English
  • TKHSAA印度尼西亚、马来西亚、菲律宾、新加坡、韩国、台湾、泰国
  • English
  • TKHSAA印度尼西亚、马来西亚、菲律宾、新加坡、韩国、台湾、泰国
  • English
  • Commend Middle Asia哈萨克斯坦、吉尔吉斯斯坦、塔吉克斯坦、土库曼斯坦和乌兹别克斯坦
  • English
  • Commend Middle Asia哈萨克斯坦、吉尔吉斯斯坦、塔吉克斯坦、土库曼斯坦和乌兹别克斯坦
  • English

Vulnerability Disclosure Policy

Commend International takes the security of our products and services seriously, and we value the security community. The coordinated disclosure process of security vulnerabilities helps us to ensure the security and privacy of our customers and users. 

This document outlines our policy for accepting security reports from our customers, external security researchers as well as disclosing security vulnerabilities found at Commend International. We gladly welcome all reports regarding vulnerabilities as per the guidelines in this policy.

Security and data protection are rooted in trust. People will accept and use solutions and services only if they are trustworthy.

Further information: 

https://trust.commend.com

https://clibrary-online.commend.com/en/cyber-security/security-advisories.html

Guidelines

Commend International requires that all researchers:

  • Respect the privacy and security of others
  • Respect the clearly defined scope 
  • Ensure that any testing is legal and authorized
  • Make reasonable efforts to contact the security team of Commend International
  • Provide sufficient information to enable us to reproduce and verify the identified vulnerability

Commend International provides to all researchers:

  • Contact address to report vulnerabilities
  • Respond to reports in a reasonable timeline
  • Clearly defined scope for our product portfolio
  • Not to pursue any legal actions related to your research
  • Open and respectful communication with all researchers
  • Publish Commend Security Advisories (CSA) and change logs
  • Offer acknowledgement within published Commend Security Advisory

Reporting Vulnerabilities

Commend International appreciates all efforts of security researchers that support us with detailed information about security vulnerabilities within our products and services. It is essential to us to have sufficient details in the initial report such that we are able to understand the full impact of the reported vulnerability. Our security team is pleased to verify and reproduce the reported vulnerability in a reasonable timeline. Hence, we will respond within 15 days.

Initial report should include:

  • Sufficient details of the vulnerability to allow it to be understood and reproduced
  • Expected impact of the vulnerability
  • Proof of concept code, script, screenshot (if available)
  • Any reference or further reading that may be appropriate (if available)
  • Recommendation on how the issue could be mitigated or resolved (if available)

Coordinated Disclosure Process

Commend International takes the security of our systems seriously. A coordinated disclosure process is required to protect our customers from any threat actors. A vulnerability report is the starting point. This action creates internally a security issue ticket which will be reviewed by our security team. The initial review results in a first draft impact analysis which concludes in a severity level according to the Common Vulnerability Scoring System (CVSS). Our Security Board members will define the next steps for each reported vulnerability. After that we contact the security researcher again and inform about the remediation plan, possible counter measures or workarounds. Although this may be enough for an easy fix, there are more complex vulnerabilities that require an ongoing discussion for clarification between our security team, the involved developers and the reporting security researcher. We appreciate an open and respectful communication as well as recommendations on how the issue could be mitigated or resolved. Our goal is to prioritize the fix of a critical or high rated vulnerability in a reasonable time by a security patch or if this is not feasible within the next official release. As a final response step the timeline for publishing a Commend Security Advisory (CSA) will be communicated. Hence, we try to fix a reported vulnerability and publish the information within 90 days.
 

All customers and security researchers are encouraged to register to our Commend Security Advisory Program:

https://clibrary-online.commend.com/en/cyber-security/security-advisories.html

This is the content of a published Commend Security Advisory:

  • Summary of vulnerability notification
  • Affected products
  • Software updates
  • Workaround or mitigation
  • Exploitation and public announcements
  • Acknowledgement
  • Sources
  • Contact and coordinated disclosure
  • Change log

Scoped Product Portfolio

Contact

support(at)commend.com

COMMEND INTERNATIONAL GMBH
Saalachstraße 51
5020 Salzburg, Austria