Security at LAUDA

Report Vulnerabilities

Security Pledge

LAUDA takes the security of its products seriously. If you have discovered a security vulnerability in one of our products, we ask that you report it to us confidentially. We will carefully review every report and work with you to find a coordinated solution.

This page serves to fulfill our obligations as a manufacturer under Regulation (EU) 2024/2847 of the European Parliament and of the Council of October 23, 2024, on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act, CRA).

Please also read our detailed CRA Statement (PDF) for further information on our cybersecurity measures.


Reporting Channel

Email: psirt@lauda.de

(PSIRT = Product Security Incident Response Team)

  • You will receive an acknowledgment of receipt within one business day.
  • For confidential reports, we recommend using our PGP key for encryption (see below).
  • Reports can be submitted in German or English.
     

Scope of the Reporting Center

In-Scope

This reporting center applies to LAUDA products with digital elements whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network—including the firmware, software, and third-party components. We accept reports of vulnerabilities in included third-party components and coordinate their resolution with the respective component manufacturer.

Out-of-Scope

  • Physical attacks on devices
  • Social Engineering
     

What should a report include?

Please include the following information in your report if possible:

  • Affected product, serial number, and software version number
  • Description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact (what can an attacker do?)
  • CVSS score, if known
  • Screenshots, logs, or proof-of-concept, if available
     

Process and SLAs for CRA Reports

Starting September 11, 2026, LAUDA will be subject to the reporting requirements under the Cyber Resilience Regulation (EU) 2024/2847. For actively exploited vulnerabilities and serious security incidents, the following deadlines must be met when reporting to the relevant authorities (CSIRT/ENISA):
 

StepDeadline
Early warning to authorities/CSIRTs≤ 24 hours after becoming aware
Report with preliminary assessment to authorities/CSIRTs≤ 72 hours
Final report (actively exploited vulnerabilities)Within 14 days of a fix or mitigation becoming available
Final report (serious security incidents)≤ 1 month after the report

 

Process and SLAs for Other Security-Related Reports

For reports not covered by the CRA reporting requirements (above), the following internal processing deadlines apply:
 

StepDeadline
Acknowledgment of receipt≤ 1 business day
Initial substantive assessment≤ 7 business days
Risk assessment and prioritizationAt our discretion
Fix/Patch or MitigationBased on risk and availability
Coordinated disclosureAfter resolution, in coordination with the parties involved

 

PGP Key

Our public PGP key is available for the encrypted transmission of your report:
 

PropertyValue
Key ID49DB91210B9E5F65
Fingerprint9A1F 8D16 460C 9799 98FA 9B2C 49DB 9121 0B9E 5F65
Valid untilJune 9, 2029


> Download PGP key (pgp-key.asc)


This page is intended exclusively for reporting security vulnerabilities in LAUDA products.
For general support inquiries, please contact: service@lauda.de

There are already three products on your comparison list.
To compare other products, please delete one of the products on your comparison list.