Sending Logs, Alerts, and Telemetry Through a Data Diode

Find Out How
We utilize artificial intelligence for site translations, and while we strive for accuracy, they may not always be 100% precise. Your understanding is appreciated.

OPSWAT Vulnerability Program

Help Strengthen Critical Infrastructure Security

The OPSWAT Vulnerability Program provides a responsible disclosure channel for security researchers to report vulnerabilities affecting eligible OPSWAT products, services, and websites. Through collaboration with the security community, we can identify, validate, and remediate issues quickly-helping our customers stay secure.

Report a Vulnerability

At OPSWAT, protecting critical infrastructure is our mission. We believe security is a shared responsibility and value the contributions of independent security researchers who help identify vulnerabilities before they can be exploited.

If you believe you have discovered a security vulnerability in an OPSWAT product or service, please submit your findings through My OPSWAT Portal.

This will redirect you to My OPSWAT Portal, where you can sign in or create an account before accessing the vulnerability submission form.

Program Scope

The Vulnerability Program* applies to eligible OPSWAT-owned products, cloud services, applications, and public-facing websites.

*Additional scope details may be provided within the submission portal. 

In Scope
Out of Scope
  • OPSWAT-hosted web applications and cloud services
  • Public-facing OPSWAT websites and portals
  • Supported OPSWAT software products
  • APIs and services owned and operated by OPSWAT
  • Third-party applications, integrations, or services
  • Automated scanning that negatively impacts service availability
  • Social engineering attacks against OPSWAT employees, partners, or customers
  • Vulnerabilities requiring physical access to customer environments
  • Physical security testing
  • Findings based solely on missing security headers, banner disclosures, or version information
  • Denial-of-service (DoS) or distributed denial-of-service (DDoS) attacks
  • Spam, phishing, or unsolicited communications
  • Reports involving unsupported, end-of-life, or unpatched third-party components unless directly attributable to OPSWAT

Responsible Disclosure Guidelines

To help us investigate and remediate issues efficiently, please:

Act in good faith to avoid privacy violations, data destruction, service disruption, or unauthorized access to customer information.

Test only against systems that are in scope for the program.

Provide sufficient detail to reproduce the vulnerability, including affected product versions, proof of concept, screenshots, logs, or other supporting evidence.

Give OPSWAT a reasonable opportunity to validate and remediate the issue before publicly disclosing details.

Immediately stop testing and notify OPSWAT if you encounter sensitive customer, employee, or proprietary data.

Duplicate reports, previously known issues, and findings that cannot be reproduced may not qualify.

Safe Harbor

OPSWAT supports responsible security research conducted in accordance with this policy. If you comply with the Vulnerability Program rules and act in good faith, OPSWAT will not pursue legal action against you for security research activities that:

  • Are conducted within the defined scope of this program
  • Do not intentionally disrupt services or systems
  • Do not access, modify, or retain customer data beyond what is necessary to demonstrate the vulnerability
  • Are promptly reported to OPSWAT through approved disclosure channels

Researchers are expected to comply with all applicable laws and regulations.

Vulnerability Severity

Eligible submissions may qualify for recognition based on severity, impact, exploitability,
and report quality.

SeverityCriticalHighMediumLow
Example ImpactRemote code execution, authentication bypass, complete compromiseSignificant privilege escalation, sensitive data exposureLimited data exposure, security control bypassLow-impact vulnerabilities with limited exploitability

Submission Process

  • Submit Report

    Submit your report through My OPSWAT Portal.

  • Receive Confirmation

    PCI DSS, SOX, DORA, GDPR, and NYDFS require strong controls around malware prevention and data protection.

  • Validate and Triage

    OPSWAT validates and triages the report.

  • Investigate and Remediate

    Our security team investigates and develops remediation plans.

  • Receive Recognition

    Qualified submissions may receive recognition.

  • Publish Security Advisory or CVE

    When appropriate, OPSWAT publishes a security advisory or CVE.

Participant represents that they are not located in, ordinarily resident in, or acting on behalf of any person located in a jurisdiction subject to comprehensive U.S. sanctions and are not listed on any applicable U.S. government restricted party list.

Questions

For questions regarding the OPSWAT Vulnerability Program, responsible disclosure practices, or vulnerability reporting, please contact the OPSWAT Security Team at psirt@opswat.com.

Together, we can strengthen cybersecurity and help protect the world's critical infrastructure.