Vulnerability Handling & Product Security at Dunkermotoren
Overview
Dunkermotoren is committed to ensuring the cybersecurity of its products, solutions, and services throughout their entire lifecycle.
To achieve this, Dunkermotoren operates a structured PSIRT (Product Security Incident Response Team) process based on established industry best practices.
This process ensures transparent, coordinated, and timely handling of security vulnerabilities.
Reporting a Vulnerability
Dunkermotoren encourages customers, partners, and security researchers to responsibly report potential vulnerabilities.
Reporting Channel
Email: psirt.dunkermotoren@ametek.com
Optional: encrypted reporting (PGP)
Required Information
- Description of the vulnerability
- Affected products / versions
- Steps to reproduce
- Potential impact
Response Time
Acknowledgment of receipt within 2 business days
Vulnerability Handling Process
All reports are processed according to a standardized workflow:
Intake & Registration
- Logging in the internal tracking system
- Initial prioritization
Analysis & Verification
- Technical analysis and reproduction
- Verification of impact
- Clarification of open questions with the reporter
Risk Assessment
- Evaluation based on CVSS (Common Vulnerability Scoring System)
- Consideration of:
- Exploitability
- Impact on availability, integrity, and confidentiality
- Deployment environment (industry / IIoT)
Mitigation & Remediation
- Collaboration with development teams
- Creation of:
- Patches / firmware updates
- Workarounds / mitigation measures
Coordinated Disclosure
Coordination with the reporter
Publication
Publication of a security advisory via BSI after a fix or appropriate mitigations are available
Security Advisory Structure
Dunkermotoren publishes standardized security advisories including:
- Advisory Title – short description
- Advisory ID – unique identifier
- Revision History – changes
- Vulnerability Description – technical details
- Affected Products – impacted products
- Impact – potential effects
- Severity (CVSS) – score and vector
- Mitigations – temporary measures
- Remediation – updates / fixes
- References – e.g., CVE
- Acknowledgement – credit to the reporter
- Contact – PSIRT contact
Disclosure Policy
Dunkermotoren follows a Coordinated Vulnerability Disclosure (CVD) approach:
- No disclosure without a fix or mitigation
- Coordination with reporters and partners
- Focus on protecting customers and industrial systems
Integration into the Product Lifecycle
- Secure Development (SSDLC)
- SBOM & component tracking
- Vulnerability monitoring (internal & external)
- Incident response