Report a vulnerability
If you think you have found a vulnerability in a Multisphera product or service, write to us confidentially. Every report is read and assessed.
Who it is for
Anyone, even if not a customer: security researchers, installers, integrators, users.
What to report
- Multisphera on-premise: web interface and modules
- Sphera-Core
- The cias-multisphera.com portal and its APIs
- The IP-Doorway2 firmware
- Related tools: setup, updates, licence packages
How to report
Write to security@cias-multisphera.com:
- a description of the problem
- the product or component and its version
- the steps to reproduce it
- the impact you expect
Do not include personal data or data about third-party systems beyond what is strictly necessary.
Do not use support tickets or public channels (social media, forums, public issue trackers) for vulnerabilities.
What we do
Acknowledgement
as soon as possible.
Assessment
of the problem and of the products involved, also with you if clarification is needed.
Fix
and release of the security update.
Notice to customers
through the signed security advisories, which reach every installation, with or without a subscription.
Coordinated disclosure
agreed with the reporter, and public credit if you wish.
Rules
- Do not run tests that degrade services or affect their availability.
- Do not access or modify other people’s data; stop as soon as you have demonstrated the problem.
- Do not test systems in operation without their owner’s authorisation.
- Keep the report confidential until the fix is available.
We will not take action against anyone who reports in good faith while following these rules.
The contact details are also published in /.well-known/security.txt. security.txt