Report a security vulnerability

You have found a possible security vulnerability in a NewTec product. We take such reports seriously and handle them in a defined process. This page tells you where to send your report and what you can expect from us.

How to reach us

By e-mail: security@newtec.de

If you want to report confidentially, please encrypt your message with our public key, available at https://www.newtec.de/security/openpgp-key_psirt.asc.

Fingerprint: F825 1CC7 CCC1 F9E0 B7B9 DFED 95F6 B315 CFAE C81E

Please do not put any details of the vulnerability in the subject line. Encryption protects the message body and its attachments, not the headers of an e-mail.

Our security.txt file is digitally signed. The public key for verifying that signature is available at https://www.newtec.de/security/openpgp-key_security-txt.asc.

Fingerprint: 5A92 5635 80E2 989E 9277 8146 7DCA 67DB BF2E 00E0

Using the form: You can also submit your report directly through the form on this page. No account is required.

Anonymous reports are accepted. No field in our form is mandatory. If you do not leave contact details, we will not be able to reply or keep you informed.

What helps us

The more precise your information, the faster we can assess whether and how our products are affected. Useful details include:

  • Which product is affected, and in which version or firmware state?
  • How can the behaviour be reproduced?
  • What impact do you see?
  • Is there any indication that the vulnerability is already being exploited?
  • Under which conditions did you test?

You are welcome to attach screenshots, log excerpts or proof-of-concept code.

What happens next

  1. We acknowledge receipt of your report: within 5 working days
  2. We assess which products are affected and reply with our findings: within 10 working days
  3. We coordinate with you how and when the vulnerability is disclosed: ongoing
  4. We publish a security advisory and credit you on request: usually within 90 days

The full rules are set out in our coordinated vulnerability disclosure policy.

Please note

This page is intended for reports about security vulnerabilities in NewTec products.

  • For general product enquiries or malfunctions, please contact your usual contact person.
  • To report an attack on NewTec's own IT systems, a different team is responsible. Please use this page in that case as well, and we will route your report internally to the team responsible.

Published security advisories

Our published advisories are available at https://www.newtec.de/en/security/advisories.

Submit a report

No field is mandatory. Fill in whatever you can contribute.

What you observed
Any indication that this is already being exploited?

Up to 4 MB in total, at most 10 files. For larger files, please send them encrypted by e-mail to security@newtec.de.

Affected product
Contact (optional)
Would you like to be credited when we publish an advisory?
Disclosure

How we handle your data

You may submit this report anonymously. No field is mandatory. We do not record an IP address for this report and we do not embed third-party services. Any details you choose to provide are used solely to process your report and to get back to you. We do not pass them on to third parties, unless this is necessary to remediate the reported vulnerability, and even then only after consulting you.