Product Security and Vulnerability Disclosure Policy
Overview
At Infortrend, we are committed to maintaining the security and reliability of our products. We continuously monitor security issues and work with customers, security researchers, and partners to identify and address potential vulnerabilities that are reported to us.
Products Scope
This policy applies to:
- Storage systems
- Server systems
- Firmware
- Embedded software
- Related product software components
Products that are at the end of their service life are not in scope.
Reporting a Security Vulnerability
If you discover a potential security vulnerability affecting our products, please contact us: security@infortrend.com
To report security vulnerabilities in Infortrend products, please include as much of the following information as possible:
- Product name and model
- Firmware/software version
- Vulnerability description
- Steps to reproduce (if available)
- Potential impact
Please note that submissions are monitored to identify potential product security issues. We will not reply to incoming messages unless further information is required. For technical support, please visit our Technical Support section instead.
Vulnerability Handling Process
Upon receiving a vulnerability report, we will:
- Review and validate the reported vulnerability
- Assess the potential impact and severity
- Investigate affected products and versions
- Develop and verify security fixes when required
- Release firmware/software updates or mitigation guidance
- Communicate relevant security information to affected customers
Responsible Disclosure
We encourage responsible disclosure practices. The customers are requested to:
- Avoid accessing, modifying, or deleting data
- Avoid disrupting product operations
- Allow reasonable time for investigation and remediation before public disclosure
Security Updates
To reduce the possibility of users being attacked by cybercrimes, Infortrend will not announce in advance the existence of vulnerabilities before issuing patches or security advisories.
Security updates and relevant security information will be provided through our official support channels and product firmware release process.
Disclaimer
This Product Security and Vulnerability Disclosure Policy is subject to change without notice. A response is not guaranteed for any specific issue.
Contact
For security-related inquiries, please contact:
Infortrend Product Security Incident Response Team
Email: security@infortrend.com