24h service hotline 4006-866-333
EN
EN CN DE
Mobile terminal
Home-About Us-Information Security
INFORMATION SECURITY

Information Security / Product Security Vulnerability Reporting

Eura Drives takes hardware and software product security very seriously. Pursuant to the EU Cyber Resilience Act (CRA) compliance requirements, this vulnerability reporting channel is set up for products placed on the EU market. You may submit a vulnerability report if you find any potential security vulnerabilities in our products.

1

Contacts

@ PSIRT
Dedicated mailbox for vulnerability reporting / Please write your email in Chinese or English
psirt@euradrives.com
We currently accept vulnerability reports only via email. Online submission forms and PGP encryption channels are not available at this time.
Note: The Eura Drives PSIRT (Product Security Incident Response Team) receives and handles all security vulnerability reports. Our goal is to work with security researchers to maintain the security and reliability of our products within a lawful and compliant framework.
2

Information Recommended for Submission Email

To help us quickly assess, reproduce and identify vulnerabilities and comply with CRA vulnerability handling requirements, please include the information below in your email to the fullest extent possible
1Vulnerability Basic Details
  1. Detailed description of the vulnerability, and the date when it was discovered;
  2. Description of scenarios where the vulnerability may be exploited;
  3. Affected product series and model (examples: E2000, SD25 servo system, EM30 inverter);
  4. Corresponding software / firmware version;
  5. Problem description and security impact, e.g., privilege escalation, information disclosure, denial of service.
2Materials Related to Vulnerability Reproduction
  1. Complete, step-by-step reproduction procedures;
  2. Proof-of-concept materials (optional): screenshots, demonstration videos, test files;
  3. Other supporting reference materials.
3Other Supplementary Information
  1. Your expected normal behavior and remediation or mitigation recommendations (if available);
  2. CVSS 3.1 vulnerability score (if available);
  3. Whether a CVE ID exists, any public papers, and the planned public disclosure date;
  4. Your contact email for follow-up communications.
3

Report Handling Process

01
Acknowledgement of Receipt
After receiving your email, we will reply as promptly as possible to confirm receipt of your report.
02
Assessment and Analysis
We will conduct a technical assessment of the vulnerability and assign risk priority. We may email you to request additional information if the submitted details are insufficient.
03
Issue Handling
For confirmed security vulnerabilities, we will carry out investigations, develop remediation plans and mitigation measures, and complete vulnerability archiving and relevant reporting in compliance with CRA requirements.
04
Result Disclosure
Where necessary, our company will release a security advisory with remediation solutions. With your consent, credit may be given to the vulnerability reporter in the advisory.
4

Important Notes

  1. By submitting the vulnerability report, you confirm that you have the right to submit such information. You also grant Eura Drives permission to use the report content for security-related work including vulnerability analysis, testing, patch development, security advisory release, and CRA-compliant archiving and reporting.

  2. We will keep the content of the vulnerability report strictly confidential and share it only with necessary technical and management personnel. Your identity as the reporter will not be disclosed to the public without your permission.

  3. Please conduct security research in compliance with applicable laws. Do not perform destructive testing on online customer equipment.

This channel applies to the reporting of security vulnerabilities in Eura Drives products placed on the EU market. Eura Drives PSIRT · All Rights Reserved