Product Security
For us at Viega, security is an integral part of our products and solutions. That is why we take product security into account right from the start and throughout the entire product lifecycle. We monitor current developments, analyse potential risks and continuously improve our solutions so that you can rely on them to work reliably. If you discover a potential vulnerability in a Viega product, we take your report seriously. On this page, you can find out how to report security vulnerabilities to us.
Report a Vulnerability
Viega is committed to the security of its products, systems and digital services. Our Product Security Incident Response Team (PSIRT) ensures a structured handling of vulnerabilities and security incidents.
Have you discovered a vulnerability?
If you have discovered a vulnerability or suspect a security incident, please report it to our Product Security Incident Response Team (PSIRT):
To help us to process your report quickly, the following information is particularly useful:
- Which product or service is affected (name, version, and article number if available)?
- How does the vulnerability manifest itself (short description)?
- How can the vulnerability be reproduced (steps, proof-of-concept if available)?
- What potential impact could the vulnerability have?
- How can we contact you for further questions?
Incomplete reports will be handled to the best of our ability. If we require additional information to validate or assess the reported vulnerability, our Product Security Incident Response Team (PSIRT) will contact you.
Product Security Incident Response Team
What happens after you submit a report?
Viega follows a Coordinated Vulnerability Disclosure process. Our goal is to minimize risks for customers while acting in a transparent manner.
- Acknowledgement of receipt: We will acknowledge your report in a timely manner.
- Assessment: We verify the vulnerability, attempt to reproduce it and assess its severity and risk.
- Mitigation: Together with the responsible product teams, we plan and implement appropriate corrective actions (e.g. updates, patches or workarounds).
- Communication: We inform affected customers and, where appropriate, publish security advisories.
Critical cases and indications of active exploitation are treated with priority. Legal requirements – for example arising from the EU Cyber Resilience Act (CRA) – may require notification of the competent authorities. Such notifications will be made in a coordinated manner and in line with our disclosure process.