Product security and vulnerability reports
The companies of the SCIO Automation Group develop and deliver automation solutions that include control, software and network components. Vulnerability handling for these products follows one common procedure across the group, and reports from outside are part of it.
If you have found a vulnerability in a product, a system or a software component of one of our companies, please report it to the address below. Every report is recorded, assessed and passed on to the company responsible. We will keep you informed about the status of the work.
Contact for security reports
PSIRT@scio-automation.com
This address is set up for security reports. For operational faults and service requests, please contact your usual service contact at the respective company.
Companies covered by this reporting channel
This channel is the common point of entry for the following companies of the SCIO Automation Group:
SCIO Automation GmbH
Dürkheimer Straße 130
67227 Frankenthal
4am Robotics GmbH
Nicolausstraße 10
94447 Plattling
Elektro Eggers GmbH
Speckmannstraße 24
28879 Grasberg
PrintoLUX GmbH
Dürkheimer Straße 130
67227 Frankenthal
SCI GmbH
Donau-Gewerbepark 30
94486 Osterhofen
SCIO Automation Austria GmbH
Industriestraße 1
8200 Albersdorf-Prebuch
SCIO Automation Duisburg GmbH
Philosophenweg 21
47051 Duisburg
SCIO Automation Ilmenau GmbH
Werner-von-Siemens-Straße 7
98693 Ilmenau
SCIO Automation Intrasolutions GmbH
Donau-Gewerbepark 30
94486 Osterhofen
SCIO Automation Ladenburg GmbH
Wallstadter Straße 59
68526 Ladenburg
SCIO Automation Production Solutions GmbH
Dürkheimer Straße 130
67227 Frankenthal
SCIO Automation Spain S.L.
Centro Tecnológico Modumaq
Av. de la Legua, 5
45005 Toledo
VESCON Aqua GmbH
Eckenförder Landstraße 87
24941 Flensburg
VESCON Energy GmbH
Dürkheimer Straße 130
67227 Frankenthal
VESCON Process GmbH
Dürkheimer Straße 130
67227 Frankenthal
The manufacturer within the meaning of Regulation (EU) 2024/2847 is the company that places the product concerned on the market under its own name. That company carries out the assessment, the remediation and the information of affected users. The common reporting channel receives your report and makes sure it reaches them.
What you can report here
Suspected or confirmed vulnerabilities in products of the companies listed, including control software, operator interfaces, application software and delivered configuration
Observations pointing to a security incident on a system delivered by us
Vulnerabilities in third-party components used in our systems. We pass such reports on to the manufacturer concerned and inform affected operators.
Information that helps us
Company, system, project or machine number concerned, as far as known
Product line and software or firmware version
Description of the behaviour and its possible effect
Steps that allow the behaviour to be reproduced
Your contact details for follow-up questions
If you prefer not to send details unencrypted, let us know by e-mail and we will agree an encrypted channel with you.
How we handle your report
You receive an acknowledgement of receipt within two working days.
We assign the report to the company responsible and examine whether and to what extent products are affected. You receive an initial assessment within ten working days.
We inform you as soon as a corrective measure is available, or let you know that in our view no measure is required, with reasons in either case.
Affected operators are informed about the necessary steps by the company responsible.
On request we will credit you as the finder in any publication, or treat your report confidentially.
Assessment and handling follow the same procedure in all companies, whichever product is affected.
What we ask of you
Give us the opportunity to remediate the vulnerability before you publish details. We suggest a period of [90 days] from your report. Where remediation takes longer, we will agree the timing with you.
Limit your testing to what is necessary, do not modify or publish third-party data, and do not access data beyond what is needed to demonstrate the vulnerability.
Only test systems in operation with the operator's consent.