PRODUCT SECURITY

Report a security incident

Use this form to report actively exploited product vulnerabilities and serious security incidents relating to ErvoCom products.

CVD Policy: Under the CVD Policy, a report must refer to a specific product and identify the integrator or system context. Relevant report information may be shared with the integrator for the joint assessment.
Do not include unnecessary personal data, credentials or detailed information about protected infrastructure. For sensitive evidence, logs, PCAPs or PoC files, we will coordinate an appropriate transfer method after receipt.

Fields marked with * are required.

1. Report type

Classification according to CVD Policy section 3.1. If unsure, select “Unclear”.
Is there evidence of active exploitation? *

2. Affected product

Provide only if necessary for identification. Do not include unnecessary customer data.

3. Integrator & system context

Name the integrator. If unknown, identify the system owner/operator (CVD Policy 6.2/6.6).
For mobile infrastructure, such as rail vehicles, provide the country of predominant operation. No exact location is required.
How is the ErvoCom product integrated? Which interfaces, peer systems or functions are relevant?

4. Technical details

Severity classification *
Are supporting files or evidence available? *

5. Reporter

Optional but recommended so we can coordinate follow-up questions and secure file transfer.

6. Confirmations

After submission you will receive an ErvoCom case ID. Please keep this reference for follow-up communication. ErvoCom Product Security will contact you if you provided contact details.