1ISO/IEC 29147 - Vulnerability Disclosure
Vulnerability Response Process Related to Our Products
Receipt of vulnerability information
If you detect any vulnerability in our products, please contact us using the web form link below. We will normally acknowledge receipt within five business days, excluding extended company holiday periods such as the Chinese New Year and year-end/New Year holidays.
When you contact us, we would appreciate your cooperation by kindly providing us with the following information as well:
Any personal information included in the information provided by you will be appropriately managed in accordance with our "Privacy Policy".
Investigation
The information provided by you regarding a vulnerability in a product will be investigated promptly by our relevant departments. We may ask you for additional information as needed.
Based on the information provided by you, we will first verify the reproducibility of the vulnerability and whether it has an impact on the product. If we determine as a result of the investigation that there is no impact on the product, we will inform you of such result and conclude our response.
If it is confirmed that there is an impact on our product, we will further investigate and analyze the root cause of the vulnerability and the scale of its impact. The status of the investigation will be shared with you as appropriate.
Countermeasures
Based on the results of our investigation into the cause of the product vulnerability and its impact, we will prepare for the implementation of countermeasures against such vulnerability and information disclosure2. Such countermeasures may include distribution of a software update or providing workarounds.
2 The period necessary for such preparation for implementation of countermeasures and information disclosure may vary depending on the level of the vulnerability risk, the scale of its impact and other related factors.
Disclosure of Vulnerability Information
As soon as we are ready to implement countermeasures against any vulnerabilities and disclose information, we will publish a security advisory containing the details of such vulnerabilities and countermeasures on the web page link below3:
Vulnerability Information
3 We may provide such information in a technical report issued by us or by individually contacting customers, etc.
When disclosing vulnerability information, we will coordinate with relevant internal and external organizations, including you and the coordinating institutions, on the release date.
Reporting Vulnerability