Die HydroElite Experience

Vulnerability Reporting

Thank you for reporting a potential security vulnerability in one of our products. We encourage responsible disclosure of security vulnerabilities. The information you provide will be used to assess, investigate, remediate, and, where required, report the vulnerability in accordance with the EU Cyber Resilience Act (CRA) and applicable cybersecurity requirements. Please provide as much information as possible. You do not need to know the severity or classification of the vulnerability; our security team will assess this.

Alternative Reporting

If preferred, you can also report vulnerabilities by send an e-mail to: vulnerabilityreporting@hydroware.se

1. Reporter Information

[Enter organisation, if applicable]
[Enter email address]
[Enter telephone number]
Preferred method of contact:

2. Affected Product

[Enter product name]
[Enter product type or model]
[Enter version]
[Enter version, if applicable]
[Enter hardware revision, if applicable]
[Enter OS/platform, if applicable]
[Describe any libraries, services, interfaces, cloud components, etc.]
Is the vulnerability present in multiple products or product versions?

3. Vulnerability Description

[Briefly describe the vulnerability]
[Describe what the vulnerability is and how it occurs]
Is the vulnerability publicly known?

4. Steps to Reproduce

Please provide clear, reproducible steps.

5. Proof of Concept

Is a proof of concept available?
Can you provide the proof of concept to us?
If yes, please provide it through the secure submission mechanism provided by our security team. Do not include passwords, authentication tokens, private keys, personal data, or other sensitive information unless specifically requested through a secure channel.

6. Security Impact

If known, please describe the potential impact.
Confidentiality impact:
Integrity impact:
Availability impact:
Potential consequences:

7. Exploitation

Have you successfully exploited the vulnerability?
Do you believe the vulnerability can be exploited remotely?
Does exploitation require authentication?
Does exploitation require physical access to the product?
Is exploitation currently occurring in the wild, to your knowledge?

8. Affected Users / Deployment

Who could potentially be affected?
Are there known mitigations or workarounds?

9. CVE / Vulnerability Identifier

Has a CVE or other vulnerability identifier already been assigned?
If you believe a CVE should be requested, please indicate:

10. Supporting Evidence

Please provide any additional information that may assist our investigation.
Logs:
Screenshots:
Configuration information:

11. Disclosure

Have you disclosed this vulnerability to any other party?
Do you intend to publicly disclose the vulnerability?

12. Reporter Declaration

By submitting this report, I confirm that:

13. Submission

Max. file size: 120 MB.