SOMMER Antriebs- und Funktechnik GmbH is committed to maintaining the security of its products and services. We value the efforts of security researchers, customers, and partners who help us identify potential security vulnerabilities.
This Coordinated Vulnerability Disclosure (CVD) Policy provides a process for reporting security vulnerabilities and describes how SOMMER will handle such reports. The Cyber Resilience Act requires manufacturers to establish a coordinated vulnerability disclosure process and a point of contact for reporting vulnerabilities.
This policy applies to products of SOMMER Antriebs- und Funktechnik GmbH within the following product areas:
For current product information please visit:
If you believe you have discovered a security vulnerability in a SOMMER product, please report it to:
Email: security@sommer.eu
To help us investigate your report, please include:
SOMMER will make reasonable efforts to:
CRA Compliance & Authority Notification:
In accordance with Article 14 of the EU Cyber Resilience Act (CRA), SOMMER is legally obligated to report any actively exploited vulnerabilities or severe security incidents to the European Union Agency for Cybersecurity (ENISA) and the competent national CSIRT within 24 hours of becoming aware of them. If a reported vulnerability falls under this category, we will trigger this official reporting process immediately in parallel to our internal remediation steps.
We kindly ask reporters to:
SOMMER will not initiate legal action against individuals who:
When appropriate, SOMMER may publish information regarding resolved security vulnerabilities, available mitigations, firmware updates, or other security-related notices.
Security advisories will be published on the SOMMER website when available.
For security-related vulnerability reports, please contact:
security@sommer.eu
SOMMER Antriebs- und Funktechnik GmbH
Hans-Böckler-Straße 27
73230 Kirchheim unter Teck
Germany