Product Security (PSIRT)
The security of our machines, control systems, software, and digital solutions is of the highest priority to F. Zimmermann GmbH . Cybersecurity and product security are integral parts of our product development process. Nevertheless, despite comprehensive development, verification, and testing procedures, security vulnerabilities can never be completely ruled out.
If you discover a potential security vulnerability affecting a Zimmermann machine, software solution, or digital service, we kindly ask you to report it to us. Your report helps us assess potential risks, take appropriate corrective actions, and continuously improve the security of our products.
Reporting a Security Vulnerability
Please send your report by email to: psirt@f-zimmermann.com
What information do we need?
To enable us to process your report as quickly and efficiently as possible, please provide the following information whenever available:
- Affected machine or product
- Machine or serial number
- Software, firmware, or control system version
- Description of the security vulnerability
- Steps required to reproduce the issue
- Potential impact (e.g., unauthorized access, manipulation, loss of availability)
- Screenshots, log files, or any other relevant technical information
Incomplete reports will also be reviewed and investigated.
Responsible Disclosure
We support the principles of Coordinated Vulnerability Disclosure (CVD) and encourage responsible reporting of security vulnerabilities. We kindly ask you to:
- Refrain from publicly disclosing the vulnerability before a coordinated solution has been developed.
- Not modify, delete, or download any data.
- Avoid conducting attacks or tests that could impair the operation, availability, or integrity of a machine or system.
All reports are treated confidentially and used exclusively for investigating and resolving the reported security vulnerability.
How We Handle Your Report
Once we receive your report, it will be evaluated by our Product Security experts. Our process includes:
- Acknowledging receipt of your report
- Technical analysis and assessment of the reported vulnerability
- Evaluating the potential impact
- Developing appropriate mitigation measures
- Informing affected customers where necessary
- Providing software updates or security patches, if applicable
Our goal is to resolve potential security risks promptly, transparently, and responsibly.
Scope
This policy applies to: F. Zimmermann GmbH portal milling machines and related online services
This policy does not apply to products, software, or services provided by third-party manufacturers or suppliers.
Data Protection
Any personal data submitted as part of your security report will be processed solely for the purpose of handling your report and in accordance with applicable data protection laws.
For further information, please refer to our Privacy Policy