Security at DESMA

Security vulnerabilities must be reported exclusively via the following email address: vulnerability@desma.de

To protect confidential information, reporters are advised to encrypt their submissions using DESMA’s public PGP key. The key is available at: https://www.desma.de/pgp-key.txt.

To the extent known and reasonable for the reporting person, a report should contain at least the following information:

1. The affected system, service, or product, including the relevant version.

2. A description of the nature of the vulnerability.

3. The steps required to reproduce the issue or a Proof of Concept (PoC).

4. An assessment of the potential impact.

5. Contact details for any follow-up questions.