PSIRT-EQUANS coordinates the response to security vulnerabilities affecting EQUANS products and services.
Are you aware of any vulnerabilities that may impact our products or services?PSIRT-EQUANS coordinates the response to security vulnerabilities affecting EQUANS products and services.
Are you aware of any vulnerabilities that may impact our products or services?
Equans Product Security Vulnerability Policy
Equans is committed to protecting the security of its products and services, customers, and partners and values the contributions of the security community in helping identify and responsibly disclose vulnerabilities.
The Product Security Incident Response Team (PSIRT) is the central point of contact for security vulnerability reports affecting supported Equans products and services. PSIRT coordinates vulnerability assessment, remediation, and disclosure in line with the FIRST Services Framework and ISO/IEC 29147 and ISO/IEC 30111 standards.
Please contact our Product Security Incident Response Team (PSIRT) for any:
- Suspected security vulnerabilities
- Actively exploited weaknesses
- Security configuration flaws
- Authentication or authorization bypass issues
- Cryptographic weaknesses
- Supply chain security concerns related to our products
For cybersecurity incidents, please contact the Equans CSIRT at csirt@equans.com.
To help Equans assess the report efficiently, please include as much of the following as possible:
- Product name and version(s)
- Platform and environment details
- Technical description of the vulnerability
- CWE classification
- Steps to reproduce
- Potential security impact (Proof-of-Concept)
- Preferred contact method for follow-up
Previously remediated issues and duplicate reports may be closed after review, but Equans will still assess them to the extent possible.
Anonymous Reporting
Vulnerability reports submitted without contact details or anonymously can only be processed to a limited extent, and in some cases, may not be processed at all due to our inability to seek clarification.
Vulnerability Handling
Equans PSIRT evaluates vulnerability reports for applicability, validity, exploitability, severity, and impact using https://www.first.org/cvss/ and other product-specific factors, including exploitability, safety impact, operational impact, exposure, and affected users as part of its standard process of evaluating reported potential vulnerabilities that do not have a CVE.
- Acknowledge receipt within five (5) business days
- Assess, triage, and prioritize the reported issue
- Contact reporter, where possible, to request additional information or clarification
- Aim to provide status updates during active investigations and periodically thereafter.
- If the vulnerability is confirmed, develop and provide appropriate mitigation measures or security updates. Where applicable, coordinate disclosure in a responsible manner.
We handle all vulnerability reports in good faith and expect reporters to act responsibly. In particular, reporters should refrain from exploiting vulnerabilities beyond what is necessary to demonstrate their existence. Equans will not initiate legal action against reporters acting in good faith, complying with this policy, and cooperating with coordinated disclosure efforts.
Reporters who responsibly disclose valid vulnerabilities may be acknowledged in security advisories, subject to consent.
If researchers encounter personal data, confidential information, or customer content during testing, they should cease testing immediately, notify Equans, and avoid copying, retaining, modifying, or disclosing such information.
- Products that have reached end-of-support generally do not receive security updates. Reports will still be reviewed to assess user risk, product dependencies, and possible impact on supported products.
- For third-party component vulnerabilities, Equans coordinates with upstream vendors, and may reference upstream CVEs within its own security advisories where this helps users identify exposure and apply remediation.
- If a reporting entity does not respond to requests for technical or content-related clarification, our ability to process the report may be limited or, in some cases, not possible.
- As per this policy, all information disclosed about new vulnerabilities is considered confidential and shall only be shared between Equans and the reporting party if the information is not already public knowledge until a remedy is available and disclosure activities are coordinated
Disclosure and Security Advisories
Equans publicly discloses validated and verified vulnerabilities unless the issue is fixed before the affected product is placed on the market and public disclosure is not required.
Validated and verified vulnerabilities will normally be disclosed within 90 days. If remediation or mitigation requires more time, disclosure may be extended further, if justified and coordinated with the corresponding national CSIRT.
The security advisories provide comprehensive details, including publication date, revision history, CVEs, affected products, CVSS scores, vulnerability descriptions, remediation guidance, mitigations, and reporter acknowledgments.
Advisories may be revised when new information becomes available. You may subscribe to security vulnerability notifications via PSIRT@equans.com
Where supported, advisories are also provided in CSAF format. As an industry-standard, machine-readable format, CSAF enables integration with security tools to fully automate the processing and interpretation of advisory data.
On a case-by-case basis, Equans may publish a Security Notice to acknowledge a publicly known security vulnerability and provide a statement or other guidance regarding when (or where) additional information will be available.
Contact for Security Matters
You may contact PSIRT using one of the preferred methods: psirt@equans.com or the web form at the bottom of the page.
For sensitive information, use the PGP key linked below and verify the fingerprint: F6687226B841B3715B8BA930EC2814B956EDAB119F10058ABD808C74A0904A6F
Disclaimer
All aspects of the Equans Product Security Vulnerability Policy are subject to change without notice. Response is not guaranteed for any specific issue or class of issues. Your use of the information in this document or materials linked herein is at your own risk.