LANGUAGE: IT | EN -
 

Coordinated vulnerability disclosure

Walvoil gives the utmost importance to cybersecurity and implements robust measures to safeguard its digital products and protect its supply chain.

The company is committed to analysing and addressing any reports of vulnerabilities promptly in order to prevent unauthorised exploitation and ensure the ongoing security of its products.

Should you discover a cybersecurity vulnerability in one of our products, please report it to our PSIRT (Product Security Incident Response Team) at the following email address: psirt@walvoil.com

WHY IS COORDINATED VULNERABILITY DISCLOSURE SO IMPORTANT?

Cyberattacks are a daily occurrence, and companies must be prepared to face and neutralize them. Investing in cybersecurity means reducing the risk exposure of all stakeholders.

Safeguarding its users, infrastructure and digital products is Walvoil's top priority. Walvoil strives for continuous improvement by pursuing cutting-edge cybersecurity. In handling all reports, we guarantee a confidential process that will involve only those Walvoil staff members strictly necessary and will prevent any transfer of information to third parties not involved in the report.

Please note that if you indicate in your report that you wish to remain anonymous, our team may be unable to contact you or interact with you in order, for example, to:
  • clarify any queries;
  • obtain further information to better understand and define the situation;
  • provide updates on the progress of the process.
Consequently, the effectiveness of resolving the reported issue may be significantly reduced.
The process for reporting and managing vulnerabilities consists of four stages.

STAGE 1 . REPORTING

To report cybersecurity vulnerabilities, please contact Walvoil’s PSIRT point of contact via the dedicated email address: psirt@walvoil.com

In particular, we would ask you to provide:

  • as much detailed information as possible about the vulnerability itself (triggering factors and so on).
  • Information about the affected product, including the product name and any relevant designations.
  • The version being used, specifying both the software version and the hardware version (if applicable) to enable accurate identification and reproduction of the problem occured.

You should only demonstrate the existence of a vulnerability by limiting your actions to what is strictly necessary.

Unless expressly authorised, you are recommended to avoid altering configurations or disrupting the normal operation of the products.



STAGE 2 . ANALYSIS AND ASSESSMENT

Walvoil will examine and attempt to reproduce the reported vulnerability in order to assess its validity and scope. This process may involve key stakeholders from various departments, thereby ensuring a thorough analysis and a comprehensive approach to resolving the issue.

Where necessary, and provided that anonymity has not been requested, the person who reported the issue may be contacted to clarify any doubts and/or to obtain further information that may help to obtain a complete overview of the situation.

Once the vulnerability has been confirmed, a risk assessment will be carried out to determine its severity and evaluate its potential impacts and consequences.

STAGE 3 . DEFINITION OF ACTIONS AND SOLUTION

Walvoil will proceed with defining, planning and deploying a resolution plan: activities may include the development of patches and updates or the optimisationof configurations.

The implementation of the aforementioned plan will follow an order of priority determined on the basis of the level of severity, impact and consequences assessed in the previous analysis.

Please note that, for phase-out products, Walvoil will only be able to provide recommendations, as it is not possible to offer corrective solutions.



STAGE 4 . DISCLOSURE

Once the reported vulnerability has been resolved, a dedicated Security Advisory will be issued on the page below:

Security Advisories

Walvoil follows a rigorous procedure for managing vulnerabilities in its products.

Our aim is to maintain the right balance between transparency and the need to allow customers sufficient time to apply the necessary corrective solutions.
Consequently, the publication of report disclosures may be postponed in order to minimise the potential impact on customers.

LEGAL NOTICE / SECURITY POLICY

During the process, the following requirements must be met:

  • Comply with applicable laws and regulations
  • Do not exploit or take advantage of vulnerabilities beyond what is strictly necessary
  • Conduct product testing without causing any adverse impact on customers and members of the public, or obtain their explicit consent in advance
  • Do not use invasive scanning tools
  • Take proper measures to prevent any potential adverse impact on the security or privacy of users
  • Do not access unnecessary and sensitive data
  • Do not modify data stored in Walvoil’ssystems
  • Securely delete all data retrieved in connection with the vulnerability report as soon as it is no longer necessary
  • Comply with the principle of coordinated disclosure, undertaking not to make the vulnerability public or share it with third parties before the expiry of the mutually agreed timeframe.

Walvoil reserves the right to take legal action in the event of non-compliance.

CONTACT FORM –REPORT

Report an issue through the contact form

THANKS SECTION

Walvoil would like to thank all the people, organizations and companies that, at their own discretion, reported and provided remediation to one or more vulnerabilities concerning our products.

Walvoil does not provide any monetary compensation (e.g. Bounty Bug) for vulnerability reports, in compliance with its Coordinated Vulnerability Disclosure (CVD) process.