Report a Security Vulnerability
If you have discovered a security vulnerability in one of our products, we kindly ask you to report it to us.
E-Mail: psirt@lt-ultra.com
PGP (Optional): Download Key
Please provide the following information in your report to help us process it efficiently:
- Reporter name (anonymous reports are also accepted)
- Contact details: Email address and phone number where we can reach you for follow-up questions
- Affiliation: Your organization, if applicable (company name, research institution, etc.)
- Description of the vulnerability (trigger, impact, and observed behavior)
- Steps to reproduce the issue
- Proof-of-Concept (if available)
- Affected components/products including version information
- Disclosure status: Has the vulnerability already been publicly disclosed?
We kindly ask you to refrain from public disclosure until appropriate mitigation measures can be implemented.
We recommend using our PGP key when transmitting confidential information.
Unencrypted reports are also accepted and will be processed accordingly.
Process After Receiving a Report
To ensure a transparent vulnerability disclosure process, all incoming reports are handled as follows:
1) Receipt of Your Report
Your report is received by our PSIRT team.
Please provide the information listed above whenever possible.
We will acknowledge receipt of your report within two business days.
2) Review and Analysis
Our PSIRT team reviews the report to determine its relevance and potential impact.
If necessary, we will contact you to request additional information or clarification.
3) Vulnerability Remediation
The PSIRT team works to:
• Fully understand the vulnerability
• Assess the associated risks and impacts
• Develop appropriate mitigation measures
4) Security Advisory and Disclosure
Once mitigation measures have been sufficiently validated, the vulnerability will be publicly disclosed.
A Security Advisory will be published.
The reporter may be acknowledged by name upon request.
Customers known to be affected will be informed directly where possible.
The advisory will be published on our website and, where required, reported to the relevant public authorities and organizations.
List of Known Vulnerabilities
Here you can find all security advisories published by the LT-Ultra PSIRT.
NONE
Contents of a Security Advisory
The publication of a vulnerability follows a standardized format and contains the following information:
Affected Components
Detailed Description of the Vulnerability
Available Mitigation Measures
If you have any questions, please contact psirt@lt-ultra.com.
A Security Advisory typically contains the following sections:
Advisory Title
A unique and descriptive title identifying the vulnerability and affected product.
Advisory ID
A unique identifier assigned to the advisory.
Revision History
Documentation of the initial publication and all subsequent updates or revisions.
Vulnerability Description
A detailed description of the vulnerability, including its type, technical characteristics, and possible root causes.
Affected Products / Solutions / Services
A list of all products, solutions, or services impacted by the vulnerability.
Impact
A description of the potential consequences if the vulnerability is exploited, including impacts on confidentiality, integrity, or availability, unauthorized access, data manipulation, data loss, or abnormal system behaviour.
Vulnerability Classification
Assessment of the vulnerability using the Common Vulnerability Scoring System (CVSS v3), including the numerical score and the complete vector string.
Temporary Mitigation
Information regarding risk-reduction measures such as:
• Workarounds
• Compensating security controls
• Recommended configuration changes
Remediation
Information about available corrective measures, including:
• Software updates
• Security patches
• Recommended upgrade paths
Additional Information
References & Disclaimer
Supporting information such as:
• Technical documentation and external references
• Legal notices
• Contact details of the Product Security Incident Response Team (PSIRT)
Acknowledgement (Optional)
Recognition of individuals or organizations that contributed to the discovery or reporting of the vulnerability, provided consent has been granted.
Your Contact
Contact our PSIRT – Product Security Incident Response Team
psirt@lt-ultra.com
