Vulnerability Reporting
Report a Security Vulnerability Responsibly
Dr. Heinrich Schneider Messtechnik GmbH takes the security of its products and software solutions seriously. If you have discovered a potential security vulnerability, please report it to us confidentially using the form below or contact our designated point of contact directly.
Point of Contact for Security Reports
Email: cra@dr-schneider.de
Telephone: +49 671 291-02
Dr. Heinrich Schneider Messtechnik GmbH
Rotlay-Mühle
55545 Bad Kreuznach
Germany
You can submit your report using the contact form, by email or by telephone.
Information to Include in Your Report
If possible, please provide the following information:
- affected product or device;
- type, model or serial number;
- software or firmware version;
- description of the vulnerability;
- potential impact;
- reproducible steps;
- date and time of discovery;
- information about any suspected or confirmed exploitation;
technical evidence, where applicable.
Please do not submit passwords, private keys, login credentials or personal data that is not required to investigate the vulnerability.
Responsible Vulnerability Disclosure
Please only conduct security testing on products and systems for which you are authorised to do so. Avoid disrupting operations or accessing or modifying third-party data. Before publicly disclosing the vulnerability, please give us reasonable time to investigate it and provide appropriate protective measures.
How We Handle Your Report
We review incoming reports and assess the affected products, the potential impact and the protective measures required.
If you provide contact details, we may:
- acknowledge receipt of your report;
- ask follow-up questions as part of our technical assessment;
- keep you informed of significant progress;
coordinate any potential public disclosure with you.
If other products or components are affected, relevant information may be shared with the responsible manufacturers, suppliers or competent security authorities. We will limit the information shared to what is necessary for the respective purpose.
Privacy Information
We process the information you provide for the purpose of reviewing, processing, remedying and documenting the reported vulnerability and, where applicable, for compliance with statutory reporting obligations.
The processing is based on our legitimate interest in ensuring the security of our products, systems and customers pursuant to Art. 6 Abs. 1 lit. f DSGVO. Where the processing is necessary for compliance with a legal obligation, it is carried out pursuant to Art. 6 Abs. 1 lit. c DSGVO.
Your information will only be made available to the internal departments and contracted service providers that require it to process the report. Where necessary, information may also be shared with manufacturers or maintainers of affected components, competent authorities, Computer Security Incident Response Teams or the European Union Agency for Cybersecurity.
The data will be stored for as long as necessary to review, remedy, track and document the vulnerability. It will subsequently be deleted unless statutory retention obligations, limitation periods or legitimate grounds require further storage.
Further information about your data protection rights, our Data Protection Officer and your right to lodge a complaint is available in our Privacy Policy.
Notice on the statutory CRA reporting obligation
This contact point is used to receive and technically assess security reports. Where the statutory requirements for a reporting obligation under Article 14 of Regulation (EU) 2024/2847 are met, the report will additionally be submitted via the designated CRA Single Reporting Platform. Contacting us via the contact form, by email or by telephone does not replace the statutory report. In particular, please state when the vulnerability or security incident was discovered and whether active exploitation has been identified.
