Coordinated Vulnerability Disclosure · v2.6

Product Security.
Built on trust.

我們以 ISO 29147、ISO 30111 與 EU Cyber Resilience Act 為基準,建立透明、可預測的漏洞協調揭露流程。

Built on ISO 29147, ISO 30111 and the EU Cyber Resilience Act, our coordinated vulnerability disclosure process is transparent and predictable.

Version 2.6Policy
ISO 29147 · 30111Standards
EU CRAAligned
3 business daysAcknowledgement target
01 · Our Commitment

政策聲明

Policy Statement

集佳股份有限公司重視產品安全。我們歡迎安全研究人員、客戶與合作夥伴,以善意通報產品中發現的潛在漏洞。

GIGA-TMS INC. takes product security seriously. We welcome good-faith reports of potential vulnerabilities from security researchers, customers, and partners.

3 個工作天是我們對通報者的初步回覆目標,不是安全或法規風險判斷的等待期。收到通報後,我們會立即進行初步分析;如有需要,將依通報程序啟動加速處理。

Our 3-business-day target is for an initial acknowledgement, not a waiting period for security or regulatory risk decisions. We begin an initial assessment upon receipt and accelerate handling when required.

本政策遵循 ISO/IEC 29147(漏洞揭露)、ISO/IEC 30111(漏洞處理)與 EU Cyber Resilience Act 之要求,確保流程透明、可預測、對善意研究者友善。

This policy follows ISO/IEC 29147 (vulnerability disclosure), ISO/IEC 30111 (vulnerability handling) and the EU Cyber Resilience Act, keeping the process transparent, predictable and researcher-friendly.

我們視安全研究社群為提升產品安全的重要夥伴,並對遵循本政策之通報者提供安全港承諾。

We consider the security research community a key partner in improving product security, and offer a safe-harbor commitment to reporters who follow this policy.

3 個工作天
初步回覆目標Acknowledgement target
風險導向
修補與揭露決策Risk-based remediation
100%
善意通報安全港Good-Faith Safe Harbor
02 · How to Report

通報管道

How to Report

本網站為純靜態漏洞通報網站;請僅以電子郵件通報。本網站不提供線上表單、檔案上傳、資料傳送、帳號登入或案件查詢功能。

This is a static vulnerability reporting site. Please report by email only; the site provides no online submission form, file upload, data transfer, account login, or case-tracking function.

Report Email
主旨請標註 [Vulnerability Report],並依第 03 節的電子郵件通報指引提供必要摘要。
Please use the subject [Vulnerability Report] and follow the email reporting guide in Section 03.

PGP Public Key

如通報含敏感技術資料或附件,請先使用本公司 PGP 公鑰加密後再附檔寄送。公鑰指紋:E25B 0966 EFFF 4F68 B78E 22A0 7874 A634 E2A6 DD17
For sensitive technical details or attachments, encrypt with our PGP public key before sending. Fingerprint: E25B 0966 EFFF 4F68 B78E 22A0 7874 A634 E2A6 DD17
03 · Email Reporting Guide

電子郵件通報指引

Email Reporting Guide

本頁僅提供靜態通報指引與郵件範本,不會蒐集、傳送或儲存任何資料。請在您的郵件應用程式中建立並寄送通報。

This page provides a static reporting guide and email template only. It does not collect, transmit, or store any information; create and send the report from your own email client.

寄送前請準備 Before you email

請在您的郵件應用程式中撰寫通報;本網站不接收或處理任何輸入內容。

  1. 寄送對象:security@gigatms.com.tw。一般通報主旨請使用 [Vulnerability Report]
  2. 必要摘要:產品型號、韌體版本、漏洞現象、重現步驟、預期/實際結果及可能影響。
  3. 敏感資訊與附件:請先下載本網站公告的 PGP 公鑰並加密,再將技術細節、PoC 或附件附於郵件。若無法加密,請先寄送非敏感摘要並要求安全團隊提供後續指示。
  4. 通報者資訊:請提供可回覆的電子郵件或代號;若願意於未來公告中致謝,請在郵件內主動說明。
緊急情況:若您認為問題具可信、立即且重大之產品安全影響,可在郵件主旨使用 [URGENT Security Report]。這僅用於協助優先分流,不代表固定公開時限或修補承諾。
For credible, immediate, high-impact product security issues, use [URGENT Security Report] to help prioritise triage; it is not a fixed disclosure or remediation SLA.

郵件範本 Email Template

請複製下列範本至您的郵件應用程式後填寫。
Copy this static template into your own email client and complete it there.

Static template
To: security@gigatms.com.tw Subject: [Vulnerability Report] <Product model> – <short issue title> Product model: Firmware / software version: Vulnerability summary: Steps to reproduce: Expected and actual result: Potential impact: Reporter contact or handle: Public acknowledgement preference (optional):
建立通報郵件 · Create Report Email
04 · Category Reference

分類參考

Category Reference

僅供通報時參考選填。選擇「其他」或留空亦可,我們將於收件時協助歸類。

For reference only when reporting. Choose "Other" or leave it blank — we will help classify it on receipt.

05 · Handling Timeline

處理時程

Handling Timeline

我們以風險、可利用性、技術複雜度與協調需求決定處理優先順序;除初步回覆目標外,不承諾固定修補或揭露天數。

We prioritise handling according to risk, exploitability, technical complexity, and coordination needs. Apart from the initial acknowledgement target, we do not commit to fixed remediation or disclosure dates.

初步回覆
Acknowledgement
3 個工作天 / Within 3 business days
初步回覆是處理目標,不是風險判斷的等待期;收到通報後即開始初步分析,必要時啟動加速分流。
The acknowledgement is a handling target, not a waiting period; initial analysis begins on receipt and accelerated triage is used when necessary.
驗證與定級
Triage
依風險分流
重現漏洞、CVSS 評估、影響範圍比對,並與通報者保持溝通。
We reproduce the issue, score it with CVSS, check its impact, and stay in touch with the reporter.
修補
Remediation
依風險與複雜度
依風險評估、可利用性、技術複雜度與相依元件情況決定修補或替代緩解措施,並在適當時機與通報者溝通進度。
Remediation or alternative mitigations are determined by risk, exploitability, technical complexity, and component dependencies; progress is communicated to the reporter as appropriate.
協調揭露
Disclosure
修補後
發布安全公告;如通報者需要,協助申請 CVE ID,並公開致謝。
We publish a security advisory, help with a CVE ID if requested, and credit the reporter publicly.

CRA Article 14 法定通報線

研究者通報線與法定通報線是兩條不同且可並行的流程。「3 個工作天」僅為回覆研究者的初步回覆目標,並不延後或取代法規風險判斷。若本公司知悉產品存在正被主動利用的漏洞,或知悉發生影響產品安全的嚴重事件,將不延遲地依適用之 CRA Article 14 流程,透過 EU 單一通報平台向協調 CSIRT 通報,並使 ENISA 同時可取得通報資訊。

Researcher communication and statutory reporting are separate and may run in parallel. The 3-business-day target concerns acknowledgement to the reporter only; it does not delay or replace regulatory risk decisions. Where the manufacturer becomes aware of an actively exploited vulnerability or a severe security incident, the applicable CRA Article 14 process is triggered through the EU single reporting platform to the coordinating CSIRT, with ENISA simultaneously able to access the notification.

正被主動利用的漏洞

自本公司知悉起,最遲 24 小時內提出早期預警;最遲 72 小時內提出漏洞通報;修補或緩解措施可用後最遲 14 日提出最終報告。

Actively exploited vulnerability: early warning within 24 hours of awareness; vulnerability notification within 72 hours; final report within 14 days after a corrective or mitigating measure becomes available.

影響產品安全的嚴重事件

自本公司知悉起,最遲 24 小時內提出早期預警;最遲 72 小時內提出事件通報;自 72 小時事件通報後一個月內提出最終報告。

Severe security incident: early warning within 24 hours of awareness; incident notification within 72 hours; final report within one month after the incident notification.
法規依據:Regulation (EU) 2024/2847, Article 14 · Official Journal
06 · Scope

適用範圍

Scope

明確界定受理與非屬本政策範圍之標的,避免混淆。

To avoid confusion, this section clearly defines what is and isn't covered by this policy.

受理範圍 In Scope

  • Promag 品牌硬體產品及其韌體Promag-branded hardware products and their firmware
  • 產品隨附之設定工具與 SDKCompanion configuration tools and SDKs
  • 產品之網路服務與管理介面Product network services and management interfaces

非本政策範圍 Out of Scope

  • 公司網站與行銷基礎設施(仍受理,轉交 IT)Corporate website / marketing infrastructure (still accepted, routed to IT)
  • 對產品或服務之阻斷式測試(DoS)Denial-of-service testing against products or services
  • 社交工程、實體入侵測試Social engineering or physical intrusion testing
07 · Safe Harbor

安全港聲明

Safe Harbor Statement

對於遵循本政策、以善意進行研究與通報之人員,本公司承諾不採取法律行動。我們視安全研究社群為提升產品安全的重要夥伴。經通報者同意,我們將於安全公告中公開致謝。

For anyone researching and reporting in good faith under this policy, we commit to taking no legal action. We view the security research community as a key partner in improving product security, and, with the reporter's consent, will credit them publicly in the advisory.