1
Contacts
@
PSIRT
Dedicated mailbox for vulnerability reporting / Please write your email in
Chinese or English
psirt@euradrives.com
We currently accept vulnerability reports only via email. Online submission
forms and PGP encryption channels are not available at this time.
Note:
The Eura Drives PSIRT (Product Security Incident Response Team) receives and handles all security
vulnerability reports. Our goal is to work with security researchers to maintain the security and
reliability of our products within a lawful and compliant framework.
2
Information Recommended for Submission Email
To help us quickly assess, reproduce and identify vulnerabilities and comply with CRA vulnerability handling requirements, please include the information below in your email to the fullest extent possible1Vulnerability Basic Details
- Detailed description of the vulnerability, and the date when it was discovered;
- Description of scenarios where the vulnerability may be exploited;
- Affected product series and model (examples: E2000, SD25 servo system, EM30 inverter);
- Corresponding software / firmware version;
- Problem description and security impact, e.g., privilege escalation, information disclosure, denial of service.
2Materials Related to Vulnerability Reproduction
- Complete, step-by-step reproduction procedures;
- Proof-of-concept materials (optional): screenshots, demonstration videos, test files;
- Other supporting reference materials.
3Other Supplementary Information
- Your expected normal behavior and remediation or mitigation recommendations (if available);
- CVSS 3.1 vulnerability score (if available);
- Whether a CVE ID exists, any public papers, and the planned public disclosure date;
- Your contact email for follow-up communications.
3
Report Handling Process
01
Acknowledgement of Receipt
After receiving your email, we will reply as promptly as possible to
confirm receipt of your report.
02
Assessment and Analysis
We will conduct a technical assessment of the vulnerability and assign risk
priority. We may email you to request additional information if the submitted details are
insufficient.
03
Issue Handling
For confirmed security vulnerabilities, we will carry out investigations,
develop remediation plans and mitigation measures, and complete vulnerability archiving and
relevant reporting in compliance with CRA requirements.
04
Result Disclosure
Where necessary, our company will release a security advisory with
remediation solutions. With your consent, credit may be given to the vulnerability reporter
in the advisory.
4
Important Notes
-
By submitting the vulnerability report, you confirm that you have the right to submit such information. You also grant Eura Drives permission to use the report content for security-related work including vulnerability analysis, testing, patch development, security advisory release, and CRA-compliant archiving and reporting.
-
We will keep the content of the vulnerability report strictly confidential and share it only with necessary technical and management personnel. Your identity as the reporter will not be disclosed to the public without your permission.
-
Please conduct security research in compliance with applicable laws. Do not perform destructive testing on online customer equipment.
This channel applies to the reporting of security vulnerabilities in Eura Drives products placed on the EU market.
Eura Drives PSIRT · All Rights Reserved
Mobile terminal