Skip navigation

Product Security


Guidelines for the Coordinated Disclosure of Vulnerabilities

Coordinated Vulnerability Disclosure Policy

EFE Elektronik-Forschungs- und Entwicklungsgesellschaft m.b.H., Mühltal

Version 1.0, effective September 1, 2026

1. Purpose and Scope

The safety of our products is a top priority for us. Our systems are used, for example, in hospitals, nursing facilities, and correctional facilities—that is, in environments where a failure could endanger people. We therefore rely on reports from security researchers, customers, installers, and third parties (hereinafter „reporters“).

This policy describes how vulnerabilities in our products and services are reported and how we handle them. It implements the requirements of Article 13(8), in conjunction with Annex I, Part II, Nos. 5 and 6, of Regulation (EU) 2024/2847 (Cyber Resilience Act, „CRA“).

1.1 Products and Systems Covered (In Scope)

  • Call systems from the Multicall product family (including Multicall Combi and Multicall Safe IP) and related components
  • ZEI Cell Terminal and Other Components of the Correctional Facility's Communication System
  • comstop detection and blocking systems, including the associated analysis and service software
  • Firmware, configuration software, service software, and update packages provided by us
  • The website www.efe-gmbh.de and the forms available there

 

1.2 Not Covered (Out of Scope)

  • Systems and equipment in operation at our customers' sites. These are under the control of the respective operator. We cannot and are not authorized to grant permission to conduct tests on such equipment.
  • Third-party products that interact with our components in customer systems (e.g., telephone systems, network components, building management systems)
  • IT systems used by our suppliers and service providers, as well as platforms operated by third parties

 

Please do not perform tests on installed systems. Call systems compliant with DIN VDE 0834 and systems in correctional facilities are safety-critical devices. Any disruption during operation can pose an immediate threat to life and limb.

Tests may only be conducted on your own equipment in a laboratory setting. If you need access to a test system for validation purposes, please contact us in advance.

 

2. Reporting a Vulnerability

This contact information is also stored in a machine-readable format in our security.txt file, in accordance with RFC 9116, at https://www.efe-gmbh.de/.well-known/security.txt.

ChannelInformation

e-mail


product-security@efe-gmbh.de

PGP key (recommended)    


Fingerprint is missing...


Web Form


CRA Reporting Form


Languages


German or English

  

If you do not wish to report directly to us, you can also contact the BSI, which serves as the national coordination center for the coordinated disclosure of vulnerabilities. We work in collaboration with coordination centers.

Helpful Information to Include in Your Report

  • Affected product, hardware and software version, or affected URL or component
  • Type of vulnerability (e.g., authentication bypass, privilege escalation, insecure update mechanism, injection, XSS)
  • Steps for reproduction, with a proof of concept if possible
  • Potential impacts, particularly on the availability of call and alarm functions
  • Your contact information for any questions

Anonymous reports are accepted. However, in such cases, we cannot provide you with a confirmation of receipt or an update on the status of your report, nor can we coordinate with you regarding its disclosure.

Please do not send us any personal data belonging to third parties, any patient or inmate data, or any extracts from customer databases. Instead, please describe the access path.

3. Our Processing Procedure

StepDeadline from the date of receipt

Confirmation of Receipt


5 business days


Initial Assessment and Triage: Plausibility, Prevalence, Severity


10 business days


Interim Results While Processing Is Underway


at least every 30 days


Workaround or security update


Prioritized based on risk, as quickly as is technically feasible


Coordinated Disclosure


in consultation with the person who filed the report; see section 5

 

Business days are Monday through Friday, excluding public holidays, at the company's headquarters in Hesse.

We assess the severity using the Common Vulnerability Scoring System (CVSS v4.0), taking into account the actual exploitability in the respective deployment environment. For confirmed vulnerabilities, we request a CVE ID as needed.

If the report concerns a third-party component, we also notify the manufacturer or the entity responsible for maintaining that component and, if necessary, provide them with corrections.

4. Legal Obligations to Report to Government Agencies

If the issue involves an actively exploited vulnerability or a serious security incident as defined in Article 14 of the CRA, we, as the manufacturer, are required—regardless of this guideline—to report it to the relevant CSIRT and ENISA via the standardized reporting platform:

  • Early warning within 24 hours of becoming aware of the situation
  • Detailed report within 72 hours
  • Final report on vulnerabilities within 14 days after a corrective measure becomes available; for serious incidents, within one month after the 72-hour notification

We will notify affected users of the vulnerability and the necessary measures in accordance with Article 14(8) of the CRA. These legal obligations exist in addition to our communication with the reporter and cannot be deferred by a confidentiality agreement. However, we will coordinate the content and timing of any public disclosure with you to the extent permitted by law.

5. Coordinated Disclosure

  • We ask that you not disclose details about a vulnerability until a fix is available or a joint deadline has been agreed upon.
  • As a general guideline, we aim to complete the disclosure within 90 days of confirmation of receipt. In cases involving complex corrections—particularly when field devices in correctional facilities or hospitals need to be updated—this deadline may be extended by mutual agreement.
  • After implementing a corrective measure, we publish a security advisory in accordance with Annex I, Part II, No. 4 of the CRA, describing the vulnerability, affected versions, impact, severity, and recommended actions.
  • Upon request, we will mention you by name in the advisory as the person who reported the issue.
  • In justified cases, we can expedite the disclosure (e.g., in the event of active exploitation) or postpone it until users have had a chance to apply the patch.

 

6. Assurances to Reporters (Safe Harbor)

We consider security research conducted in good faith and in accordance with this policy to be authorized by us.

We will not file any civil claims against reporters who comply with this policy, nor will we file any criminal charges against them. The prerequisite is that you

  • test only systems as specified in section 1.1, and only its own devices in a test environment,
  • do not retrieve, modify, delete, or disclose any third-party data,
  • do not impair the systems beyond what is necessary for verification,
  • Do not leave behind any malware, backdoors, or permanent access,
  • keep the vulnerability confidential until the agreed-upon disclosure,
  • not to sell or disclose the information to third parties.

This assurance applies exclusively to rights over which we have control. It does not extend to claims by third parties, in particular operators of systems, and it does not prevent law enforcement agencies from taking action ex officio. It does not apply to actions that go beyond the identification of the reported vulnerability, such as data exfiltration, extortion, denial-of-service attacks, or disclosure to third parties.

If third parties take legal action against you as a result of an investigation conducted in accordance with this policy, we will, upon request, confirm that the action was authorized by us.

7. Exclusions and No Bug Bounty Program

This policy does not establish a bug bounty program. There is no entitlement to compensation.

This directive does not apply to, among other things:

  • Social Engineering and Phishing Targeting Employees
  • Physical attacks on sites, facilities, or equipment
  • Denial-of-Service and Spam Attacks
  • Pure best-practice recommendations without evidence of exploitability—such as missing HTTP security headers or results from automated scans that have not been verified
  • Vulnerabilities in products whose support period has expired. We accept such reports and notify affected users, but generally do not provide any further updates.

 

8. Support Period and Security Information

We determine the support period for each product based on its expected useful life. It is at least five years from the date of market introduction and is correspondingly longer for the long-lasting systems in our product families. The specific details can be found in the respective product documentation.

We make security updates available for at least ten years after their release, or for the remainder of the support period, whichever is longer.

We publish security advisories and information about security updates at https://www.efe-gmbh.de/security-advisories/.

We maintain a software bill of materials (SBOM) for our products in accordance with Annex I, Part II, No. 1 of the CRA. It is made available to market surveillance authorities upon request. We provide customers with product-specific SBOM information in accordance with our contractual agreements.

9. Data Protection

We process personal data from your report solely for the purpose of addressing the vulnerability, providing you with feedback, and fulfilling statutory reporting obligations. The legal bases are Article 6(1)(c) and (f) of the GDPR. Your contact information will only be shared with the CSIRT or ENISA to the extent necessary for reporting in accordance with Article 14 of the CRA. We retain reports and related correspondence as evidence of vulnerability mitigation for the duration of the support period for the affected product. For more information, please see our Privacy Policy.

10. Contact

EFE Elektronik-Forschungs- und Entwicklungsgesellschaft m.b.H. An der Flachsröste 3 64367 Mühltal Germany

Email: product-security@efe-gmbh.de General inquiries: info@efe-gmbh.de

11. Revision History

Version
Date
Revision
1.0
September 1, 2026
Initial Release