Vulnerability Tracking
Before submitting vulnerability information here, please read our vulnerability disclosure
policy (VDP) below.
💡 We accept emails at security@dqmh.org and can engage in back-and-forth conversation there.
When you choose to share your contact information with us, we commit to coordinating with you
as openly and as quickly as possible.
- Within 3 business days, we will acknowledge that your report has been received.
- To the best of our ability, we will confirm the existence of the vulnerability to you and be
as transparent as possible about what steps we are taking during the remediation process,
including on issues or challenges that may delay resolution. - We will maintain an open dialogue to discuss issues.
Vulnerability Disclosure Policy
Introduction
The DQMH Consortium is committed to the security of the products we publish and of the
applications our users build with them. This policy is intended to give security researchers
clear guidelines for conducting vulnerability discovery activities and to convey our
preferences in how to submit discovered vulnerabilities to us.
Reporting a vulnerability
We accept vulnerability reports via security@dqmh.org. Reports may be submitted
anonymously. If you share contact information, we will acknowledge receipt of your report
within 3 business days.
This policy describes what products and types of research are covered under this policy, how to
send us vulnerability reports, and how long we ask security researchers to wait before publicly
disclosing vulnerabilities.
This policy covers the products we publish — DQMH, DTS and DCFG — as distributed
through VIPM and dqmh.org, together with the dqmh.org and documentation.dqmh.org websites. It
does not cover applications that others have built using our toolkits, or installations operated
by our users; please do not test systems you do not own. If you find an issue in a third-party
component we ship or depend on, report it to us and we will coordinate with its maintainer.
We encourage you to contact us to report potential vulnerabilities in our products.
If you make a good faith effort to comply with this policy during your security research, we
will consider your research to be authorized, we will work with you to understand and resolve
the issue quickly, and the DQMH Consortium will not recommend or pursue legal action related to
your research. Should legal action be initiated by a third party against you for activities that
were conducted in accordance with this policy, we will make this authorization known.
What we would like to see from you
In order to help us triage and prioritize submissions, we recommend that your reports:
- Describe the location the vulnerability was discovered and the potential impact of exploitation.
- Identify the product and version affected, and the LabVIEW version and platform used.
- Offer a detailed description of the steps needed to reproduce the vulnerability (proof of
concept VIs, scripts or screenshots are helpful). - Be in English or German, if possible.
What you can expect from us
When you choose to share your contact information with us, we commit to coordinating with you as
openly and as quickly as possible.
- Within 3 business days, we will acknowledge that your report has been received.
- To the best of our ability, we will confirm the existence of the vulnerability to you and be as
transparent as possible about what steps we are taking during the remediation process,
including on issues or challenges that may delay resolution. - We will maintain an open dialogue to discuss issues.
- When we publish a security update, we will publish information about the fixed vulnerability so
that users can assess their exposure and act. - Where a reported vulnerability is being actively exploited, we may be legally required to notify
the relevant authorities. We will tell you if that applies to your report.
Guidelines
Under this policy, “research” means activities in which you:
- Notify us as soon as possible after you discover a real or potential security issue.
- Make every effort to avoid privacy violations, degradation of user experience, disruption to
production systems, and destruction or manipulation of data. - Only use exploits to the extent necessary to confirm a vulnerability’s presence. Do not use an
exploit to compromise or exfiltrate data, establish persistent command line access, or use the
exploit to pivot to other systems. - Test only against your own installation of our products.
- Provide us a reasonable amount of time to resolve the issue before you disclose it publicly. We
aim to remediate without delay, and ask that you hold publication until a fix is available or
90 days have passed, whichever comes first. - Do not submit a high volume of low-quality reports.
Once you’ve established that a vulnerability exists or encounter any sensitive data (including
personally identifiable information, financial information, or proprietary information or trade
secrets of any party), you must stop your test, notify us immediately, and not disclose this data
to anyone else.
Test methods
The following test methods are not authorized:
- Network denial of service (DoS or DDoS) tests or other tests that impair access to or damage a
system or data - Physical testing (e.g. office access, open doors, tailgating), social engineering (e.g.
phishing, vishing), or any other non-technical vulnerability testing - Testing against installations operated by our users or customers