We welcome reports of product vulnerabilities and work closely with reporters to assess and fix issues. Our PSIRT ensures secure mobility and coordinates responsible disclosure across all our products.
Introduction
We are committed to developing products and services which are secure in order to enable safe, exciting, connected, and autonomous mobility. We welcome any information about potential product cybersecurity vulnerabilities or exploits from researchers, academics, or others in the broader security community.
Our Product Security Incident Response Team (PSIRT) will enthusiastically work with those who bring forward such vulnerabilities as we constantly strive to improve the security posture of products and services.
For the safety of our customers and consumers, we kindly request that you not publish or share the information with other third parties until reported vulnerabilities can be properly assessed and mitigated. We greatly appreciate the efforts made to identify and report issues to our company and look forward to hearing from you.
Program scope
This disclosure program is valid for all our products and those previously sold under the label of Continental Automotive.
Our PSIRT will not respond to reports relating to public-facing infrastructure and strongly encourages you to contact the responsible department at cybersecurity@aumovio.com. Further information on reporting requirements can be found at IT cyber incident reporting hotline.
Disclosure program details
For all product-related security vulnerabilities please write to psirt@aumovio.com and include as much of the following as possible:
- Name and version of the affected product
- Any part or product identifiers on product packaging
- Technical description of the identified issue, including a proof of concept if possible
- Details on how to reproduce the issue
- Any plans for future public disclosure
Our PSIRT processes align with the FIRST PSIRT Framework as follows:
Discovery: After you report an issue in one of our products, we will confirm reception of the information, usually within two business days.
Triage: We will work with our relevant product departments to identify the correct project team to handle the case. They will review the information provided and verify that the vulnerability exists in the reported product. Customers and suppliers which are impacted by the confirmed vulnerability will be notified in accordance with established agreements.
Remediation: In alignment with our customers, we will develop and release mitigations to reduce the risks of the vulnerability. When possible, we will coordinate with the reporter to confirm effectiveness of mitigations.
Disclosure: We will coordinate with the reporter on further disclosure of the information. As a member of the Auto-ISAC, we will share relevant security vulnerabilities to other Auto-ISAC members which may also be impacted by the reported information. We would like to recognize and give credit to you for submissions made through this program and we respect your option to remain anonymous if desired.