Initiatives Regarding Product Security
In order to ensure a high level of product security and protect our customers against cyber attacks, MESW discloses vulnerability information related to our products in the following process.
Reporting
If you believe that one of our products has a potential vulnerability, please contact the Mitsubishi Electric Product Vulnerability Reporting Desk below.
Vulnerability report form
https://www.mitsubishielectric.com/psirt/contact/index.html
After receiving the vulnerability information via the report form, we will reply within 5 business days. Please note that our reply will be a little late during Japan’s public holidays and MESW’s own holidays, etc.
The above product vulnerability reporting channel accepts only undisclosed vulnerabilities in our products. With regards to products other than those manufactured by MESW, please contact the manufacturer of the respective product.
The report form is encrypted with SSL/TLS. After the reporter contacts us via the report form, we will communicate with the reporter by e-mail. If the e-mail and/or attachments contain sensitive information about undisclosed vulnerabilities, please encrypt the e-mail and/or attachments with our PGP public key to prevent unintentional disclosure. We will notify the reporter of the PGP public key individually in response to a submission.
Investigation and Countermeasures
The relevant product design and development department will investigate the vulnerability information the reporter provided, and if the following three conditions are met, it will be determined as a new vulnerability and we will immediately notify the result of the investigation to the reporter. We may request additional information as necessary.
Vulnerability criteria:
- 1.Identifies a true product security issue.
- 2.The vulnerability is able to be reproduced.
- 3.The vulnerability is undisclosed.
Should a vulnerability be found, we will implement countermeasures and prepare to disclose a new vulnerability. If it is not a new vulnerability, we will close the investigation and notify the reporter of our conclusion. However, please understand that we may not investigate vulnerabilities in EOL (End Of Life) products. We consider a product to be EOL when both its manufacturing/sales and support have ended.