Skip to content
CIAS Multisphera
Security

Report a vulnerability

If you think you have found a vulnerability in a Multisphera product or service, write to us confidentially. Every report is read and assessed.

Who it is for

Anyone, even if not a customer: security researchers, installers, integrators, users.

What to report

  • Multisphera on-premise: web interface and modules
  • Sphera-Core
  • The cias-multisphera.com portal and its APIs
  • The IP-Doorway2 firmware
  • Related tools: setup, updates, licence packages

How to report

Write to security@cias-multisphera.com:

  • a description of the problem
  • the product or component and its version
  • the steps to reproduce it
  • the impact you expect

Do not include personal data or data about third-party systems beyond what is strictly necessary.

Do not use support tickets or public channels (social media, forums, public issue trackers) for vulnerabilities.

What we do

  1. Acknowledgement

    as soon as possible.

  2. Assessment

    of the problem and of the products involved, also with you if clarification is needed.

  3. Fix

    and release of the security update.

  4. Notice to customers

    through the signed security advisories, which reach every installation, with or without a subscription.

  5. Coordinated disclosure

    agreed with the reporter, and public credit if you wish.

Rules

  • Do not run tests that degrade services or affect their availability.
  • Do not access or modify other people’s data; stop as soon as you have demonstrated the problem.
  • Do not test systems in operation without their owner’s authorisation.
  • Keep the report confidential until the fix is available.

We will not take action against anyone who reports in good faith while following these rules.

The contact details are also published in /.well-known/security.txt. security.txt