Safety Information
If you have discovered one or more vulnerabilities related to the use of a Hoffmann + Krippner product, please feel free to contact us.
To help us process your vulnerability report quickly and efficiently, please include the following information:
- Your contact information, if you would like to be contacted, or you may remain anonymous and use an anonymous email forwarding service
- The type of vulnerability identified (product / infrastructure)
- How long have you been aware of the vulnerability?
- Is the vulnerability being actively exploited?
- Your item number
- The Hoffmann + Krippner part number and serial number
- The firmware or software version
- A description of the potential hazard
- Is personal information involved?
- Is there a violation of the law?
- The affected interface
- Description of the Impact of the Vulnerability
- Description of the Exploitation of the Vulnerability
- Additional comments, images, or videos
How to Report a Potential Vulnerability
For security reports, please use our designated reporting form.
Alternatively, you can contact our security teams at the following email addresses:
Product Security Incident Response Team (PSIRT)
For security vulnerability reports at the product level:
Computer Security Incident Response Team (CSIRT)
For security alerts at the infrastructure level, such as cyberattacks or data breaches:
The following public PGP keys are available for encrypted communication:
PGP Key PSIRT-HMI
ID: 1B47681479FA52AB
Fingerprint: 1E90 DFA1 C17F 8510 E860 E50A 1B47 6814 79FA 52AB
PGP Key CSIRT
ID: 4DCE2017C6640A24
Fingerprint: BAB3 63A6 2AE7 6CB8 D7A3 6F6A 4DCE 2017 C664 0A24
Please send us your message, preferably in German or English.