EU Cyber Resilience Act (CRA)

Vulnerability Reporting

Our instruments protect people in some of the most hazardous places they’ll ever work. That only holds true if the products and systems behind them are secure. If you believe you’ve found a security vulnerability in a Crowcon product, hardware, firmware, or software, tell us straight away, through our Coordinated Vulnerability Disclosure (CVD) process below.

This process is built around the EU Cyber Resilience Act and the industry standards for vulnerability disclosure and handling (ISO/IEC 29147 and 30111). Reporting helps us keep every customer running our equipment safe, and keeps us compliant with our obligations under EU law.

How to report a vulnerability

Complete the form with as much detail as you can.

1. Product identification

  • Product name and model number
  • Product serial number (if relevant)
  • Firmware or software version
  • Date of purchase (optional)

2. Vulnerability details

  • Type of vulnerability (for example: cross-site scripting, buffer overflow, authentication bypass, firmware tampering)
  • Description of the issue

3. Impact

  • What you believe the risk is
  • Whether it’s currently being exploited

4. Your contact details

  • Name (optional)
  • Email address
  • Preferred way for us to reach you (optional)
  • Company name 
  • Country

Please don’t disclose the vulnerability publicly until we’ve had reasonable time to address it. We are committed to working with you under a standard CVD timeline.

 

What we’ll do

  • Acknowledge your report within 3 business days.
  • Investigate it and prioritise a fix based on severity.
  • Keep you updated as we work through it.
  • Coordinate with you on the timing of any public disclosure once a fix is ready.
  • Publish an advisory for affected customers covering what’s changed and what they need to do.

If a vulnerability is being actively exploited, or it’s tied to an incident that seriously affects product security, the Cyber Resilience Act requires us to notify ENISA and the relevant national CSIRT.