SOMMER Group
Deutschland

Coordinated Vulnerability Disclosure (CVD) Policy

SOMMER Coordinated Vulnerability Disclosure Policy

SOMMER Antriebs- und Funktechnik GmbH is committed to maintaining the security of its products and services. We value the efforts of security researchers, customers, and partners who help us identify potential security vulnerabilities.

This Coordinated Vulnerability Disclosure (CVD) Policy provides a process for reporting security vulnerabilities and describes how SOMMER will handle such reports. The Cyber Resilience Act requires manufacturers to establish a coordinated vulnerability disclosure process and a point of contact for reporting vulnerabilities.


Scope

This policy applies to products of SOMMER Antriebs- und Funktechnik GmbH within the following product areas:

  • Smart Home products
  • IP Cameras

For current product information please visit:


Reporting a Vulnerability

If you believe you have discovered a security vulnerability in a SOMMER product, please report it to:

Email: security@sommer.eu

To help us investigate your report, please include:

  • Product name
  • Product version and/or firmware version
  • Description of the vulnerability
  • Steps required to reproduce the issue
  • Potential impact
  • Your contact information

Our Commitment

SOMMER will make reasonable efforts to:

  • Acknowledge receipt of your report within 2 business days
  • Provide an initial assessment within 7 days
  • Provide status updates at least every 14 days until resolution or closure

CRA Compliance & Authority Notification:

In accordance with Article 14 of the EU Cyber Resilience Act (CRA), SOMMER is legally obligated to report any actively exploited vulnerabilities or severe security incidents to the European Union Agency for Cybersecurity (ENISA) and the competent national CSIRT within 24 hours of becoming aware of them. If a reported vulnerability falls under this category, we will trigger this official reporting process immediately in parallel to our internal remediation steps.


Responsible Disclosure

We kindly ask reporters to:

  • Act in good faith
  • Avoid actions that could negatively affect the confidentiality, integrity, or availability of systems or data
  • Avoid accessing, modifying, or deleting data that does not belong to them
  • Refrain from publicly disclosing vulnerabilities before a remediation or mitigation has been made available
  • Provide sufficient information to allow validation and reproduction of the issue

Safe Harbor

SOMMER will not initiate legal action against individuals who:

  • Act in good faith
  • Follow this policy
  • Do not exploit vulnerabilities beyond what is reasonably necessary to demonstrate their existence
  • Do not exfiltrate data
  • Do not intentionally damage, disrupt, or impair SOMMER systems, products, or services

Security Advisories

When appropriate, SOMMER may publish information regarding resolved security vulnerabilities, available mitigations, firmware updates, or other security-related notices.

Security advisories will be published on the SOMMER website when available.


Contact

For security-related vulnerability reports, please contact:

security@sommer.eu

SOMMER Antriebs- und Funktechnik GmbH
Hans-Böckler-Straße 27
73230 Kirchheim unter Teck
Germany