PSIRT · 产品安全事件响应团队/PSIRT · Product Security Incident Response Team

漏洞披露政策(Vulnerability Disclosure Policy)

科力光电鼓励全球安全研究人员、组织主动提交产品安全漏洞, 共同守护工业与物联网安全。

Keli Photoelectronic encourages global security researchers and organizations to proactively submit product security vulnerabilities, working together to secure industrial and IoT ecosystems

psirt@sdkeli.com 1 个工作日内确认(Confirm within 1 business day)
科力 PSIRT 简介 Introduction to Keli PSIRT

科力光电 PSIRT 为科力产品安全事件响应团队(KELI Product Security Incident Response Team)。 科力 PSIRT 负责产品相关漏洞的接收、核查和披露。 科力光电鼓励全球安全从业人员、组织等主动提交您发现的科力光电产品的安全漏洞, 帮助我们持续提升产品安全性。 科力 PSIRT 将遵循 ISO/IEC 30111ISO/IEC 29147 等行业标准处理科力相关产品。

Keli Photoelectronic PSIRT, short for KELI Product Security Incident Response Team, is the dedicated product security response team of Keli. Keli PSIRT is responsible for the receipt, verification and disclosure of product-related vulnerabilities. Keli Photoelectronic encourages global security practitioners, organizations and other parties to proactively submit any security vulnerabilities discovered in Keli Photoelectronic products, to help us continuously improve product security. Keli PSIRT will handle Keli-related products in strict compliance with industry standards including ISO/IEC 30111 and ISO/IEC 29147.

提交范围 Submission Scope

科力光电服务范围内的产品。

Products Covered by Keli Photoelectronic Services

提交途径 Submission Pathway

邮箱 Email:psirt@sdkeli.com

回复机制 Response Mechanism
  • 1 个工作日 内邮件回复确认 Confirmation will be sent via email within 1 business day
  • 7 个工作日 内收到漏洞验证结论 Vulnerability verification results will be available within 7 business days
提交指引 Submission Guidelines
  1. 使用模板完整、准确填写。 Fill out the template completely and accurately using the template provided
  2. 由于安全漏洞属于敏感信息,为确保其机密性,强烈建议您使用科力光电的 PGP(Pretty Good Privacy)公钥 进行加密。 Since security vulnerabilities are sensitive information, to ensure their confidentiality, you are strongly recommended to encrypt the content with the PGP (Pretty Good Privacy) public key of Keli Photoelectronic
  3. 邮件主题:产品名称-漏洞简述 Email Subject: Product Name - Brief Vulnerability Description
报告应包含(但不限于) The report shall include (but is not limited to)
安全港说明 Safe Harbor Statement

如果您在遵循本政策的前提下善意地开展安全研究,我们将视您的研究为授权行为, 不会针对您的结果提起法律诉讼。 但是禁止将漏洞公开披露。 If you conduct security research in good faith in compliance with this policy, we will regard your research as an authorized act and will not file legal proceedings against your research results. However, public disclosure of the vulnerabilities is strictly prohibited.

报告披露原则 Principles for Vulnerability Report Disclosure

科力光电采用 CVD(协调漏洞披露)机制,通常不会立即披露安全漏洞, 而是经过与报告方协商,再进行漏洞审查确认,通常在有修复或缓解措施后进行披露。 如果是特殊情况,比如无法立即解决或存在特定风险,披露时间会根据实际情况调整。 Keli Photoelectronic adopts the CVD (Coordinated Vulnerability Disclosure) mechanism. Normally, we will not disclose security vulnerabilities immediately. Instead, we will conduct vulnerability review and confirmation after full consultation with the vulnerability reporter, and the disclosure will usually be carried out after the corresponding fix or mitigation measures are available. For special scenarios where the vulnerability cannot be resolved immediately or there are specific security risks, the disclosure timeline will be adjusted according to the actual situation.

漏洞处理流程 Vulnerability Handling Process
1
漏洞接收 Vulnerability Receipt

接收产品的安全漏洞。 Receive product security vulnerabilities

2
分析验证 Analysis and Verification

确认漏洞的有效性和影响范围。 Confirm the validity and scope of impact of the vulnerability

3
漏洞修复 Vulnerability Remediation

修复存在的漏洞或采用降低风险的措施。 Remediate existing vulnerabilities or adopt risk mitigation measures‌

4
信息发布 Information Disclosure

向客户和相关部门发布漏洞信息。 Release vulnerability information to customers and relevant departments

5
优化改进 Optimization and Improvement

进行复盘,持续优化。 Conduct post-incident reviews for continuous optimization

科力 PSIRT 对以上内容具有最终解释权。Keli PSIRT reserves the right to final interpretation of all of the above

提交漏洞 Submit Vulnerabilities

请将漏洞报告发送至 psirt@sdkeli.com Please send your vulnerability report to psirt@sdkeli.com

立即提交

建议使用 PGP 加密

科力光电版权所有 2018-2028 网站备案号:鲁ICP备14008611号