Product Security / PSIRT

Reporting vulnerabilities responsibly – for secure products, digital solutions and services from GRIMME.

Working together for safe products and digital solutions

The early detection and responsible handling of vulnerabilities is an essential part of product security at GRIMME. At GRIMME, the security of products, digital solutions and services is a top priority. To support responsible disclosure and continuous improvement, GRIMME operates a Product Security Incident Response Team (PSIRT). External third parties can report potential vulnerabilities to GRIMME via a publicly accessible and permanently available reporting channel. Reports are treated confidentially and can be submitted without prior authentication.

How to report a vulnerability

How to report a vulnerability

If you have discovered a potential vulnerability, you can report it to GRIMME PSIRT by telephone. To ensure your report is processed quickly, please provide as much of the following information as possible.

Affected product or system

Software or firmware version

Description of the identified vulnerability, including, where applicable, a CVE (Common Vulnerabilities and Exposures) identifier

Description of the impact

Optional: Reproduction steps or proof of concept

Optional: Contact details for enquiries

Documentation of vulnerabilities

Once the analysis has been completed and the issue resolved, GRIMME publishes security advisories on relevant vulnerabilities in an appropriate format. 

These security advisories contain at least: 

  • a clear description of the vulnerability and its implications
  • details of the affected products and versions
  • specific recommendations and measures for secure use 

The publication may (subject to agreement) be coordinated with the reporting bodies.  



Current safety information: 

Safety information
Year
There are currently no published safety notices.

Guidelines and Notes

This policy applies to all publicly accessible GRIMME systems, applications and services, unless expressly excluded. 

Not covered: 

  • Denial-of-service (DoS) or load testing
  • Social engineering
  • Physical attacks
  • Attacks on third parties or suppliers 

Contact:

GRIMME Landmaschinenfabrik SE & Co. KG

Hunteburger Straße 32 

DE-49401 Damme 

PSIRT Contact: +49 5491 6660