科力光电 PSIRT 为科力产品安全事件响应团队(KELI Product Security Incident Response Team)。 科力 PSIRT 负责产品相关漏洞的接收、核查和披露。 科力光电鼓励全球安全从业人员、组织等主动提交您发现的科力光电产品的安全漏洞, 帮助我们持续提升产品安全性。 科力 PSIRT 将遵循 ISO/IEC 30111、ISO/IEC 29147 等行业标准处理科力相关产品。
Keli Photoelectronic PSIRT, short for KELI Product Security Incident Response Team, is the dedicated product security response team of Keli. Keli PSIRT is responsible for the receipt, verification and disclosure of product-related vulnerabilities. Keli Photoelectronic encourages global security practitioners, organizations and other parties to proactively submit any security vulnerabilities discovered in Keli Photoelectronic products, to help us continuously improve product security. Keli PSIRT will handle Keli-related products in strict compliance with industry standards including ISO/IEC 30111 and ISO/IEC 29147.
科力光电服务范围内的产品。
Products Covered by Keli Photoelectronic Services
邮箱 Email:psirt@sdkeli.com
- 1 个工作日 内邮件回复确认 Confirmation will be sent via email within 1 business day
- 7 个工作日 内收到漏洞验证结论 Vulnerability verification results will be available within 7 business days
- 使用模板完整、准确填写。 Fill out the template completely and accurately using the template provided
- 由于安全漏洞属于敏感信息,为确保其机密性,强烈建议您使用科力光电的 PGP(Pretty Good Privacy)公钥 进行加密。 Since security vulnerabilities are sensitive information, to ensure their confidentiality, you are strongly recommended to encrypt the content with the PGP (Pretty Good Privacy) public key of Keli Photoelectronic
- 邮件主题:产品名称-漏洞简述 Email Subject: Product Name - Brief Vulnerability Description
- 漏洞描述及危害说明 Vulnerability description and impact statement
- 受影响的产品和版本 Affected products and versions
- 复现步骤 Reproduction steps
- 技术细节和证据(如概念验证、截图、日志文件等) Technical details and supporting evidence (such as proof of concept, screenshots, log files, etc.)
安全港说明 Safe Harbor Statement
如果您在遵循本政策的前提下善意地开展安全研究,我们将视您的研究为授权行为, 不会针对您的结果提起法律诉讼。 但是禁止将漏洞公开披露。 If you conduct security research in good faith in compliance with this policy, we will regard your research as an authorized act and will not file legal proceedings against your research results. However, public disclosure of the vulnerabilities is strictly prohibited.
科力光电采用 CVD(协调漏洞披露)机制,通常不会立即披露安全漏洞, 而是经过与报告方协商,再进行漏洞审查确认,通常在有修复或缓解措施后进行披露。 如果是特殊情况,比如无法立即解决或存在特定风险,披露时间会根据实际情况调整。 Keli Photoelectronic adopts the CVD (Coordinated Vulnerability Disclosure) mechanism. Normally, we will not disclose security vulnerabilities immediately. Instead, we will conduct vulnerability review and confirmation after full consultation with the vulnerability reporter, and the disclosure will usually be carried out after the corresponding fix or mitigation measures are available. For special scenarios where the vulnerability cannot be resolved immediately or there are specific security risks, the disclosure timeline will be adjusted according to the actual situation.
接收产品的安全漏洞。 Receive product security vulnerabilities
确认漏洞的有效性和影响范围。 Confirm the validity and scope of impact of the vulnerability
修复存在的漏洞或采用降低风险的措施。 Remediate existing vulnerabilities or adopt risk mitigation measures
向客户和相关部门发布漏洞信息。 Release vulnerability information to customers and relevant departments
进行复盘,持续优化。 Conduct post-incident reviews for continuous optimization
科力 PSIRT 对以上内容具有最终解释权。Keli PSIRT reserves the right to final interpretation of all of the above
请将漏洞报告发送至 psirt@sdkeli.com Please send your vulnerability report to psirt@sdkeli.com
立即提交建议使用 PGP 加密