close
QUNDIS Portal

Coordinated Vulnerability 

Disclosure Policy

Manufacturer: Qundis GmbH
Version: 1.0
Created: 27 August 2026
Last modified: 27 August 2026
Next review: 27 August 2027
 

1. Overview and Scope

Qundis GmbH welcomes responsible reports of suspected security vulnerabilities affecting our products and infrastructure. Researchers and other parties who identify a potential vulnerability can submit a report to our security team by email. Please provide sufficient information to enable us to understand, reproduce, and assess the reported issue.

This CVD Policy applies to vulnerabilities affecting Qundis GmbH products and infrastructure.

Qundis GmbH reviews this policy at least once per year and keeps it up to date.
 

2. Vulnerability Reporting

Vulnerabilities can be reported through:

cyber-security@qundis.com 

Qundis GmbH accepts vulnerability reports by email only.

Qundis GmbH treats all incoming vulnerability reports to the best extent possible. No incoming report is closed by a single analyst.

A valid vulnerability is a vulnerability affecting a Qundis GmbH product or Qundis GmbH infrastructure.
 

3. Confidentiality and Reporting Entity Protection

Qundis GmbH treats each vulnerability report confidentially to the extent permitted by law. Information required for public disclosure of a vulnerability is excluded from this confidentiality obligation.

Personal data of the reporting entity is not disclosed to third parties without the explicit consent of the reporting entity.

Qundis GmbH will not pursue criminal charges against a reporting entity that complies with this policy and its principles. This does not apply where recognizable criminal intentions have been or are being pursued.

Qundis GmbH remains available as a contact for a trustful exchange throughout the entire CVD process.

Reporting vulnerabilities is appreciated and helps Qundis GmbH improve the security of its products and services. However, submission of a vulnerability report does not create any entitlement to a monetary reward, bounty, or other financial compensation.
  
4. Content of Vulnerability Report

To help assess and investigate a reported vulnerability efficiently, as much relevant information as possible should be provided. A complete report should include, where applicable:

  • Identification of the affected Qundis GmbH product, component, firmware, software version, or service.
  • Clear description of the suspected vulnerability, including its root cause and the security implications identified.
  • Description of any specific configuration, deployment conditions, permissions, authentication requirements, or other prerequisites needed to reproduce the issue.
  • Clear, detailed, step-by-step instructions allowing to independently reproduce and verify the vulnerability.
  • Where available, proof of concept, test case, screenshots, logs, or exploit code demonstrating the issue. For code-scanning findings, evidence demonstrating actual exploitability is required.
  • Description of the potential consequences of successful exploitation, including the assets, data, systems, or users that could be affected and the level of access an attacker could obtain.
  • Any other technical details, indicators, logs, or supporting evidence that may assist in validating and assessing the vulnerability.
     

5. Out of Scope Elements

The following issues are generally considered outside the scope of this Coordinated Vulnerability Disclosure process:

  • Vulnerabilities that have already been publicly disclosed or assigned a CVE, or that have already been addressed through a security update or other remediation, unless the report provides significant new information, demonstrates a previously unknown security impact, or identifies an incomplete or ineffective remediation.
  • Vulnerabilities affecting products, software, services, or versions that have reached end-of-life or are no longer supported by Qundis GmbH.
  • Vulnerabilities affecting versions for which Qundis GmbH has advised customers to upgrade or migrate to a supported version, where the reported issue is resolved in the recommended version.
  • Findings that do not present a meaningful security impact, including purely informational findings, general security recommendations, or weaknesses that cannot reasonably be exploited in the affected environment.
  • Issues that rely primarily on social engineering, phishing, spam, or attacks targeting Qundis GmbH personnel, customers, or other third parties rather than a vulnerability in a Qundis GmbH product or service.
  • Reports generated solely by automated scanning tools without sufficient information to reproduce or validate the issue.
  • Vulnerabilities affecting third-party products or services that are not developed, maintained, or operated by Qundis GmbH. Such third-party issues should be reported to the respective vendor or service provider.
+49 361 26 280-0 info@qundis.com