PESA Vulnerability Disclosure Programme

 

Working together for better security

We at PESA Cybersecurity team are committed to ensuring the security and resilience of our products, services, and digital environment.

We value the contributions of cybersecurity researchers, customers, partners, and other members of the cybersecurity community who help us identify and address potential cybersecurity vulnerabilities.

If you are convinced you have discovered a cybersecurity vulnerability affecting any PESA vehicle, we encourage you to report it through our official Vulnerability Disclosure Program.

Before you start

Please review our Integrated Vulnerability Disclosure Policybefore undertaking any security testing activities.

The policy defines:

  • Which products are within scope
  • Official channels for reporting vulnerabilities
  • The handling and coordination process
  • PESA’s commitments under the Cyber Resilience Act (CRA)
  • Rules of engagement (Safe Harbor)
  • The availability of updates and the communication process regarding vulnerabilities

Only products explicitly defined within the scope of the policy are authorized for security testing.

How to report vulnerabilities

  1. Review the Policy
  2. Prepare Your Report
    To help us efficiently assess your finding, please include:
    • A clear description of vulnerability
    • The affected product or service
    • The location of the vulnerability (relevant URL or component)
    • The steps required to reproduce the issue
    • The potential cybersecurity impact
    • Relevant evidence such as screenshots, logs, or Proof-of-Concept (PoC) information
    • Your contact details, unless you prefer to report anonymously

    Please do not include personal data or proprietary or sensitive information unless it is necessary to explain the vulnerability.

  3. Securely Submit Your Report via provided communication channels:

Important information

The Vulnerability Disclosure Program is intended solely for reporting potential cybersecurity vulnerabilities.

It must not be used for:

  • General customer inquiries
  • Product support requests
  • Operational incidents
  • Physical security concerns
  • Reporting hazards related to railway operations

If there is an immediate threat to human health or life, railway operations, or physical security, please contact the appropriate emergency services or relevant authorities.

Our involvement

As the PESA Cybersecurity Team, we appreciate the time and effort invested by cybersecurity researchers who responsibly report potential vulnerabilities in accordance with our policy.

Reports submitted through the Vulnerability Disclosure Program will be reviewed and handled in accordance with the process defined in the policy.

Together, we can strengthen the security and cyber resilience of PESA’s products, services, and digital environment.