Coordinated Vulnerability Disclosure Policy

Coordinated Vulnerability Disclosure Policy (CVD)

1. Purpose and Scope

ETA a.s. (hereinafter referred to as "ETA") hereby establishes a Coordinated Vulnerability Disclosure (CVD) policy in accordance with Regulation (EU) 2024/2847 on Cyber Resilience (CRA).
The policy applies to all ETA products with digital elements placed on the market in the European Economic Area, including their firmware, accompanying mobile applications, and connected cloud services. The policy applies for the entire support period of each product, but for at least 5 years from placing on the market.

2. Contact Channel for Vulnerability Reporting

Vulnerabilities in ETA products can be reported through the following channels:

Channel Address
E-mail psirt@eta.cz
Web https://www.etasince1943.com/product-security/
security.txt (RFC 9116) https://www.eta.cz/.well-known/security.txt

We accept reports in Czech, Slovak, and English. Anonymous reports are also possible.

2.1 What to Include in a Report

For quick assessment, please provide:

  • name and version of the affected product or firmware,
  • description of the vulnerability and its potential impact,
  • steps to reproduce, if possible,
  • contact information or a request to remain anonymous.

3. Deadlines for Report Processing

Activity Deadline
Confirmation of report receipt within 3 business days
First substantive response (triage) within 10 business days
Regular status update at least once every 14 days
Remediation — critical vulnerability (CVSS 9.0–10.0) within 7 calendar days
Remediation — high vulnerability (CVSS 7.0–8.9) within 30 calendar days
Remediation — medium vulnerability (CVSS 4.0–6.9) within 90 calendar days
Remediation — low vulnerability (CVSS 0.1–3.9) within 180 calendar days

Deadlines may be reasonably extended if coordination with a third-party supplier is necessary. ETA shall inform the finder thereof without undue delay.

4. Report Processing Procedure

Step Description
1 — Receipt The report is registered, a tracking number is assigned to the finder, and receipt is acknowledged within 3 business days.
2 — Triage The PSIRT team verifies reproducibility, determines severity (CVSS), and identifies affected products and versions.
3 — Remediation The responsible development team drafts a patch or mitigation within the stipulated deadlines.
4 — Testing The patch undergoes security testing and verification.
5 — Update Release The fix is released and distributed to users via standard update channels.
6 — Publication ETA publishes a security advisory containing the description of the vulnerability, CVSS score, and guidance for users.

5. Coordinated Disclosure

Information about a vulnerability is published after the release of a patch or effective mitigation. ETA coordinates the publication date with the finder; the standard embargo is 90 days from the confirmation of the report.

5.1 Security Advisory Content

Each security advisory contains:

  • CVE identifier and CVSS v3.1 severity rating,
  • affected products and versions,
  • description of the vulnerability and exploitation conditions,
  • remediation instructions or recommended actions,
  • machine-readable version in CSAF 2.0 format.

5.2 Publication Channels

6. Reporting Obligations

Upon detecting an actively exploited vulnerability or a severe security incident, ETA is obliged, starting from September 11, 2026, to report this fact to ENISA and the national CSIRT.CZ via the EU Single Reporting Platform:

For the purposes of this article, a severe security incident means an incident that (a) negatively affects the product's ability to protect the availability, authenticity, integrity, or confidentiality of data or functions, OR (b) has led or may lead to the introduction of malicious code into the product or the user's network.

Event Type Early warning Initial notification Final report
Actively exploited vulnerability 24 hours 72 hours 14 days from patch availability
Severe security incident 24 hours 72 hours 30 days from initial notification

The deadlines for early warning and initial notification start from the moment ETA detects active exploitation or a severe incident — not from the moment the report is received from the finder. The deadline for the final report of an actively exploited vulnerability runs from the moment a corrective or mitigating measure is available. The deadline for the final report of a severe incident runs from the moment the initial notification is sent.

7. SBOM and Third-Party Component Management

ETA compiles and maintains a Software Bill of Materials (SBOM) for each product with digital elements. The SBOM is prepared in a machine-readable format (SPDX or CycloneDX) and contains at least the most critical product dependencies. The SBOM is updated with each release of a new version and is made available to market surveillance authorities upon request.

If third-party components (libraries, chipset firmware, SDKs) are included in an ETA product, ETA monitors security advisories from the respective suppliers and addresses vulnerabilities in such components in accordance with the deadlines set out in Section 3 of this policy. Upon detecting a vulnerability in a third-party component, ETA shall promptly inform the relevant supplier and coordinate remediation.

Public PGP Key

Link to download PGP key