Vulnerability Disclosure and Reporting Policy

Vulnerability Disclosure Policy 
The timely discovery and reporting of security vulnerabilities help minimize information security risks and enhance product security. Genesys Logic has established a Product Security Incident Response Team (PSIRT) responsible for receiving and handling information security incidents and security vulnerability reports related to Genesys Logic products.

 
  1. Vulnerabilities covered by this policy must be related to Genesys Logic products.
  2. Upon receiving a vulnerability report, Genesys Logic will follow a process that includes initial response, preliminary assessment and classification, technical investigation, and vulnerability remediation. Relevant information will be communicated to customers after remediation has been completed.
  3. Genesys Logic endeavors to provide an initial response within five (5) business days of receiving a vulnerability report. If no response is received within the above-mentioned period, please resubmit your report.
  4. Prior to the release of a security patch and the publication of the corresponding security advisory, reporters are requested to refrain from publicly disclosing technical details that could facilitate malicious exploitation of the vulnerability in order to reduce information security risks.
  5. This Policy applies only to security research conducted in good faith. Testing activities must comply with all applicable laws and regulations and must not cause service disruption, data corruption, unauthorized access, or otherwise adversely affect Genesys Logic, its customers, suppliers, or any third party.
  6. Genesys Logic reserves the right to modify or update this Policy and the related processes at any time without prior notice.

Vulnerability Reporting Process
If you discover a suspected security vulnerability in any Genesys Logic product, please report it via email and include the following information.

  1. Product name and specific software/firmware version.
  2. Hardware and software environment in which the issue occurred.
  3. A summary of the vulnerability and its potential impact.
  4. Root cause analysis of the vulnerability.
  5. Steps to reproduce the issue and supporting evidence (e.g., screenshots, images, or source code).
  6. Proof of Concept (PoC).
  7. Any additional information that may assist our investigation.

Email:PSIRT@genesyslogic.com.tw

 Vulnerability Severity Assessment
Genesys Logic adopts the Common Vulnerability Scoring System (CVSS) v3.1 as the standard for assessing the risk level and severity of identified security vulnerabilities.