Vulnerability Handling & Product Security at Dunkermotoren

Overview

Dunkermotoren is committed to ensuring the cybersecurity of its products, solutions, and services throughout their entire lifecycle.

To achieve this, Dunkermotoren operates a structured PSIRT (Product Security Incident Response Team) process based on established industry best practices.

This process ensures transparent, coordinated, and timely handling of security vulnerabilities.

Reporting a Vulnerability

Dunkermotoren encourages customers, partners, and security researchers to responsibly report potential vulnerabilities.

Reporting Channel

Email: psirt.dunkermotoren@ametek.com
Optional: encrypted reporting (PGP)

Required Information

  • Description of the vulnerability
  • Affected products / versions
  • Steps to reproduce
  • Potential impact

Response Time

Acknowledgment of receipt within 2 business days

Vulnerability Handling Process

All reports are processed according to a standardized workflow:

Intake & Registration

  • Logging in the internal tracking system
  • Initial prioritization

Analysis & Verification

  • Technical analysis and reproduction
  • Verification of impact
  • Clarification of open questions with the reporter

Risk Assessment

  • Evaluation based on CVSS (Common Vulnerability Scoring System)
  • Consideration of:
    • Exploitability
    • Impact on availability, integrity, and confidentiality
    • Deployment environment (industry / IIoT)

Mitigation & Remediation

  • Collaboration with development teams
  • Creation of:
    • Patches / firmware updates
    • Workarounds / mitigation measures

Coordinated Disclosure

Coordination with the reporter

Publication

Publication of a security advisory via BSI after a fix or appropriate mitigations are available

Security Advisory Structure

Dunkermotoren publishes standardized security advisories including:

  • Advisory Title – short description
  • Advisory ID – unique identifier
  • Revision History – changes
  • Vulnerability Description – technical details
  • Affected Products – impacted products
  • Impact – potential effects
  • Severity (CVSS) – score and vector
  • Mitigations – temporary measures
  • Remediation – updates / fixes
  • References – e.g., CVE
  • Acknowledgement – credit to the reporter
  • Contact – PSIRT contact

Disclosure Policy

Dunkermotoren follows a Coordinated Vulnerability Disclosure (CVD) approach:

  • No disclosure without a fix or mitigation
  • Coordination with reporters and partners
  • Focus on protecting customers and industrial systems

Integration into the Product Lifecycle

  • Secure Development (SSDLC)
  • SBOM & component tracking
  • Vulnerability monitoring (internal & external)
  • Incident response