Security at DESMA
Security vulnerabilities must be reported exclusively via the following email address: vulnerability@desma.de
To protect confidential information, reporters are advised to encrypt their submissions using DESMA’s public PGP key. The key is available at: https://www.desma.de/pgp-key.txt.
To the extent known and reasonable for the reporting person, a report should contain at least the following information:
1. The affected system, service, or product, including the relevant version.
2. A description of the nature of the vulnerability.
3. The steps required to reproduce the issue or a Proof of Concept (PoC).
4. An assessment of the potential impact.
5. Contact details for any follow-up questions.