The more precise the report, the faster the fix. The useful minimum:
Enclosure reference, HAI-OS version (the “Update System Manager” page), and the add-on involved where relevant.
The steps, the minimal request or script, the network setup used. A screenshot or a trace file helps a lot.
What an attacker would gain: data disclosure, authentication bypass, code execution, denial of service…
The name or handle you want credited in the fix — or your preference to stay anonymous.
On those terms we treat your work as legitimate research and will take no action against you. We run no bounty programme — but we are grateful, and we say so publicly.
Regulation (EU) 2024/2847, the Cyber Resilience Act, places cybersecurity obligations on manufacturers of products with digital elements — an industrial gateway is one of them. It applies in stages:
Every manufacturer must report to ENISA and the national CSIRT any actively exploited vulnerability or severe incident affecting the security of its product: early warning within 24 h, notification within 72 h, then a final report — within 14 days of a fix becoming available for a vulnerability, within one month of the notification for a severe incident. In France reporting is centralised through CERT-FR.
The full set of obligations applies to products placed on the market from that date: essential security requirements, technical documentation, vulnerability handling over the support period, and CE marking.
The reporting duty sits with the manufacturer, not the operator. You have nothing to notify for a gateway you use — that is our job. Yours is to apply the updates we publish.
This page describes how we receive and handle reports. It does not replace our contractual terms and is not a legal interpretation of the regulation: for the official reading in France, refer to ANSSI's publications.
Use support: it is tracked and it lands directly with the team building the product. The security channel is reserved for issues with a security impact.