MENU

SECURITY

Secure embedded and IoT solutions for a connected world.



Security Advisories

This section lists all public security advisories, vulnerability notices, and machine-readable CSAF 2.0 records for COLIGO, BE.services, and eTSN products.

There are currently no active security advisories. When advisories are published, they will be listed here in human-readable format and as downloadable CSAF 2.0 JSON records.




Policy Statement

BE.services GmbH (including COLIGO and eTSN) maintains a Coordinated Vulnerability Disclosure (CVD) program aligned with the EU Cyber Resilience Act (Regulation (EU) 2024/2847) and ISO/IEC 29147.

This policy governs how we receive, investigate, coordinate, and remediate security vulnerabilities across our digital products and embedded software. It applies to security researchers, industry partners, customers, and any third party reporting potential flaws.


Scope

This policy covers all digital and connected products manufactured or actively maintained by BE.services GmbH, including:


  • COLIGO SYNA EdgeBox (Hardware and base system firmware)
  • COLIGO EdgeStack & COLIGO Apps
  • eTSN SDK (OPC UA FX / TSN stacks and integration components)
  • Official cloud services, management portals, and public APIs under our direct control


Excluded from scope:

  • Products and software versions that have reached their declared End-of-Life (EOL) or are no longer actively supported.
  • Third-party cloud infrastructure or services not operated by BE.services.
  • Denial-of-Service attacks (DoS/DDoS) against public web infrastructure or customer industrial production lines.

How to Report a Vulnerability

If you have discovered a vulnerability, report it directly to our product security team

PGP Encryption


Fingerprint: CB2B C14B 8896 C23F B663 265A C078 7487 A9E3 D4EF


We accept reports in English and German. Please do not submit security vulnerabilities through public ticket systems, customer support chats, or social media.

What to Include in Your Report

To help us triage and validate your submission quickly, please include:

  • Target Product: Exact product model, hardware revision, and software/firmware version.
  • Classification: Suspected CWE type (e.g., CWE-78, CWE-120) and CVSS score (if calculated).
  • Vulnerability Summary: Clear explanation of the flaw and potential industrial/operational impact.
  • Reproduction Steps: Step-by-step instructions or minimal, non-destructive proof-of-concept (PoC) code/scripts.
  • Components: If the issue resides in an upstream open-source or commercial library, identify the component name and version.
  • Disclosure Status: Indicate whether the vulnerability is already known publicly or observed in the wild.
  • Your Details: Preferred name or pseudonym for attribution in our advisory (or specify if you wish to remain anonymous).

Response Commitments

BE.services commits to timely, professional communication throughout the disclosure lifecycle

Stage


Acknowledgment

Triage & Validation

Status Updates

Security Updates

Security Advisory

Target Timeline


Within 48 hours of receipt

Within 5 business days

At least every 30 calendar days until remediation

Delivered as soon as practicable, free of charge

Published concurrently with or immediately following patch availability



Safe Harbour

BE.services values constructive security research conducted in good faith. We will not initiate civil litigation or make criminal complaints against researchers who

  • Comply strictly with this Coordinated Vulnerability Disclosure policy.
  • Confine testing to the minimum necessary to demonstrate the vulnerability without causing operational downtime, service degradation, or safety hazards in industrial environments.
  • Do not access, modify, exfiltrate, or delete personal data (under EU GDPR) or proprietary customer production data.
  • Maintain confidentiality and give us reasonable time to remediate before disclosing details publicly or to third parties.



Coordinated Disclosure & Advisories

We adhere to coordinated vulnerability disclosure and request a standard 90-day embargo period from confirmed validation to patch release before any public disclosure.

Once resolved, we publish public security advisories on this page (and machine-readable CSAF 2.0 JSON records). Our advisories contain

  • CVE identifier (where assigned via CNA)
  • CVSS v3.1 / v4.0 severity score and vector
  • Affected and remediated product versions
  • Remediation instructions, workarounds, and free patch download links
  • Credit to the reporting researcher (unless anonymity was requested)

If an actively exploited flaw requires user intervention to protect systems before a permanent patch can be deployed, we will issue early customer guidance and mitigation notices without undue delay in accordance with CRA requirements.



Supply Chain Coordination

Where a validated vulnerability originates in an integrated third-party or open-source component, BE.services will

  • Notify the upstream component manufacturer or maintainer within 5 business days of confirming the vulnerability.
  • Coordinate disclosure timelines and embargo dates to prevent premature exposure of upstream projects.
  • Share any relevant remediation patches, modifications, or technical documentation upstream in accordance with CRA Article 13(6).
  • Reference upstream security advisories and CVEs within our own published advisory.