Product security and vulnerability reports
The companies of the SCIO Automation Group develop and deliver automation solutions that include control, software and network components. Vulnerability handling for these products follows one common procedure across the group, and reports from outside are part of it.

If you have found a vulnerability in a product, a system or a software component of one of our companies, please report it to the address below. Every report is recorded, assessed and passed on to the company responsible. We will keep you informed about the status of the work.

Contact for security reports
PSIRT@scio-automation.com

This address is set up for security reports. For operational faults and service requests, please contact your usual service contact at the respective company.

Companies covered by this reporting channel
This channel is the common point of entry for the following companies of the SCIO Automation Group:

SCIO Automation GmbH 
Dürkheimer Straße 130 
67227 Frankenthal
 
4am Robotics GmbH 
Nicolausstraße 10 
94447 Plattling 
 
Elektro Eggers GmbH 
Speckmannstraße 24 
28879 Grasberg 
 
PrintoLUX GmbH 
Dürkheimer Straße 130 
67227 Frankenthal 
 
SCI GmbH 
Donau-Gewerbepark 30 
94486 Osterhofen 
 
SCIO Automation Austria GmbH 
Industriestraße 1 
8200 Albersdorf-Prebuch 
 
SCIO Automation Duisburg GmbH 
Philosophenweg 21 
47051 Duisburg 
 
SCIO Automation Ilmenau GmbH 
Werner-von-Siemens-Straße 7 
98693 Ilmenau  
 
SCIO Automation Intrasolutions GmbH 
Donau-Gewerbepark 30 
94486 Osterhofen 
 
SCIO Automation Ladenburg GmbH 
Wallstadter Straße 59 
68526 Ladenburg 
 
SCIO Automation Production Solutions GmbH 
Dürkheimer Straße 130 
67227 Frankenthal 
 
SCIO Automation Spain S.L. 
Centro Tecnológico Modumaq 
Av. de la Legua, 5 
45005 Toledo 
 
VESCON Aqua GmbH 
Eckenförder Landstraße 87 
24941 Flensburg 
 
VESCON Energy GmbH 
Dürkheimer Straße 130 
67227 Frankenthal 
 
VESCON Process GmbH 
Dürkheimer Straße 130 
67227 Frankenthal

The manufacturer within the meaning of Regulation (EU) 2024/2847 is the company that places the product concerned on the market under its own name. That company carries out the assessment, the remediation and the information of affected users. The common reporting channel receives your report and makes sure it reaches them.

What you can report here
Suspected or confirmed vulnerabilities in products of the companies listed, including control software, operator interfaces, application software and delivered configuration
Observations pointing to a security incident on a system delivered by us
Vulnerabilities in third-party components used in our systems. We pass such reports on to the manufacturer concerned and inform affected operators.

Information that helps us
Company, system, project or machine number concerned, as far as known
Product line and software or firmware version
Description of the behaviour and its possible effect
Steps that allow the behaviour to be reproduced
Your contact details for follow-up questions
If you prefer not to send details unencrypted, let us know by e-mail and we will agree an encrypted channel with you.

How we handle your report
You receive an acknowledgement of receipt within two working days.
We assign the report to the company responsible and examine whether and to what extent products are affected. You receive an initial assessment within ten working days.
We inform you as soon as a corrective measure is available, or let you know that in our view no measure is required, with reasons in either case.
Affected operators are informed about the necessary steps by the company responsible.
On request we will credit you as the finder in any publication, or treat your report confidentially.
Assessment and handling follow the same procedure in all companies, whichever product is affected.

What we ask of you
Give us the opportunity to remediate the vulnerability before you publish details. We suggest a period of [90 days] from your report. Where remediation takes longer, we will agree the timing with you.
Limit your testing to what is necessary, do not modify or publish third-party data, and do not access data beyond what is needed to demonstrate the vulnerability.
Only test systems in operation with the operator's consent.