Tex Automation (CVD)
Coordinated Vulnerability Disclosure Policy
PUBLIC POLICY FOR REPORTING, HANDLING AND COORDINATED DISCLOSURE OF CYBERSECURITY VULNERABILITIES
1. Purpose
Tex Automation welcomes reports from customers, machine manufacturers, system integrators, security researchers and other parties concerning potential cybersecurity vulnerabilities in Tex Automation products. This policy explains how to submit a report, how Tex Automation handles and coordinates the report, and how information about a confirmed and remediated vulnerability will be communicated and publicly disclosed in accordance with applicable legal requirements.
This policy supports the vulnerability-handling requirements of Regulation (EU) 2024/2847 (Cyber Resilience Act), including the establishment and enforcement of a coordinated vulnerability disclosure policy and the provision of a contact address for reporting vulnerabilities.
2. Scope
This policy applies to all Tex Automation hardware, firmware and software, including associated configuration, programming, update and maintenance tools.
Vulnerabilities in third-party components integrated into a Tex Automation product are within the scope of this policy where they affect the security of that product.
Tex Automation accepts reports concerning all products. For products and versions within their declared support period, Tex Automation will address and remediate identified vulnerabilities without delay.
Corrective measures may include security updates, mitigations, configuration guidance or other appropriate remediation. For products outside the support period, Tex Automation may provide risk information, mitigations, upgrade guidance or replacement recommendations where reasonably practicable.
A reported issue may be outside Tex Automation product scope when it concerns only:
- third-party products or infrastructure not supplied or controlled by Tex Automation;
- customer-developed machine applications, unless the issue is caused by a Tex Automation product vulnerability;
- customer networks, remote-access systems or security controls not supplied by Tex Automation;
- social engineering, fraud or physical-security issues unrelated to a Tex Automation product vulnerability.
3. How To Report A Potential Vulnerability
Send reports to: PSIRT@texautomation.it
Reports may be submitted in English or Italian. Please use a clear subject line, for example: “Potential vulnerability report – [product name/model]”.
Where available, include:
- product name and model;
- hardware revision and serial number, where relevant;
- firmware or software version;
- description of the potential vulnerability and the observed behaviour;
- steps required to reproduce the issue;
- proof-of-concept information or diagnostic evidence;
- potential impact on confidentiality, integrity, availability, machine operation or safety;
- whether exploitation has been observed or is suspected;
- reporter name, organisation and contact details;
- preferred method for continued communication.
Sensitive information. Tex Automation does not currently provide a public PGP key or public secure-upload portal.
Do not include credentials, customer production data, confidential machine programs, personal data or detailed exploit material in the initial email. State that sensitive information is available; Tex Automation will arrange an appropriate communication method where required.
4. Responsible Reporting And Testing Conditions
Testing shall be conducted only on systems owned by the reporter or where the reporter has explicit authorization from the system owner. Because Tex Automation products may control industrial machinery, testing must not create a risk to persons, machinery, production or the environment.
Reporters are requested to:
- use a non-production or otherwise controlled test environment;
- avoid accessing, altering, copying or deleting data beyond what is necessary to demonstrate the issue;
- avoid persistence, lateral movement, social engineering and physical intrusion;
- avoid denial-of-service, resource-exhaustion and high-volume automated testing;
- avoid any test that may cause machine movement, unexpected output activation, loss of control or a hazardous condition;
- stop testing immediately if a safety, operational, privacy or data-protection risk becomes apparent;
- provide Tex Automation with a reasonable opportunity to investigate and address the issue before public disclosure;
- coordinate the timing and content of any public disclosure with Tex Automation.
This policy does not authorise unlawful activity and does not grant immunity from civil, criminal, contractual or regulatory consequences.
5. Monitoring and acknowledgement
Reports may be sent at any time. The PSIRT mailbox is monitored during the following business hours:
- Monday to Friday: 08:00–13:00 and 14:00–17:00
- Time zone: Europe/Rome local time (CET/CEST)
- Saturday and Sunday: closed
Tex Automation aims to acknowledge receipt of a vulnerability report within 2 to 5 working days. This is a service objective and may be affected by report completeness, product availability, holidays or exceptional operational circumstances.
6. Tex Automation Handling Process
Tex Automation will handle reports through a documented vulnerability-management process. As applicable to the reported issue, the process includes:
- Registering the report and assigning a case identifier.
- Confirming the affected product, version and support status.
- Assessing whether the reported behavior constitutes a cybersecurity vulnerability.
- Evaluating severity, exploitability, potential operational or safety impact, and evidence of active exploitation.
- Identifying other products, versions or third-party components that may be affected.
- Defining corrective measures, security updates, mitigations or operational guidance.
- Verifying and validating the corrective measure.
- Coordinating communication with the reporter and affected customers, machine manufacturers or system integrators.
- Publishing or distributing vulnerability information and remediation instructions where appropriate.
- Retaining the case record and relevant evidence.
Where reasonably practicable, Tex Automation will provide status updates at significant stages of the investigation. The nature and frequency of updates will depend on the complexity, severity and sensitivity of the case.
7. Assessment And Prioritization
Tex Automation may use a documented severity-scoring method, such as the Common Vulnerability Scoring System (CVSS), together with product-specific engineering judgement. Assessment factors may include:
- required access and privileges;
- ease and reliability of exploitation;
- affected products and versions;
- impact on confidentiality, integrity and availability;
- impact on machine control, production continuity or safety;
- availability of mitigations or compensating controls;
- evidence of active exploitation;
- support status and deployment context.
8. Corrective Measures And Security Updates
Where a confirmed vulnerability requires action, Tex Automation will address and remediate the vulnerability without delay during the applicable support period. Remediation may include one or more of the following:
- a firmware or software security update;
- a revised configuration or parameter setting;
- instructions to disable or restrict an affected service or protocol;
- network-segmentation, firewall or access-control measures;
- operational restrictions or temporary mitigations;
- upgrade, replacement or migration guidance.
Security updates and related instructions will be distributed securely and without delay through authorised Tex Automation channels or through the relevant machine manufacturer or system integrator.
Security updates will be accompanied by clear information describing the actions affected users should take. Security updates will be provided free of charge, unless otherwise agreed between Tex Automation and a business user in relation to a tailor-made product with digital elements.
Where technically feasible, new security updates will be provided separately from functionality updates.
9. Coordinated Disclosure
Tex Automation will determine disclosure timing case by case, taking into account severity, active exploitation, potential safety consequences, availability of a correction or mitigation, validation requirements, and the time reasonably required by affected machine manufacturers, system integrators and users to implement corrective measures.
Once a security update or other effective corrective measure is available, Tex Automation will publicly disclose information about the fixed vulnerability. The information will enable affected users to identify the relevant product and affected versions, understand the nature, impact and severity of the vulnerability, and apply the available remediation or mitigation. Public disclosure may be delayed only in duly justified cases where the security risks of publication outweigh the security benefits, and only until affected users have had the possibility to apply the relevant patch or other corrective measure.
Tex Automation requests that reporters do not publicly disclose vulnerability details before a coordinated disclosure date has been agreed or before affected users have had a reasonable opportunity to apply available corrective measures.
10. Security Advisories And Customer Notification
Relevant security advisories, corrective measures and mitigation instructions will be communicated to affected customers through their machine manufacturer or system integrator, or directly by Tex Automation where a direct customer relationship exists.
A security advisory concerning a fixed vulnerability will include, at minimum:
- affected products and versions;
- a description of the vulnerability;
- the impact and severity of the vulnerability;
- the available correction, mitigation or operational guidance;
- the fixed version, where available, and clear remediation or mitigation instructions.
Where appropriate, the advisory may also include an advisory identifier, publication date, known-exploitation status and revision history.
11. Reporter Acknowledgement
With the reporter’s explicit consent, Tex Automation may acknowledge the reporter or the reporter’s organisation in a security advisory. Acknowledgement may be withheld where attribution would create confidentiality, privacy, legal, contractual, safety or operational concerns.
Tex Automation does not currently operate a bug-bounty or financial-reward programme.
Submission of a report does not create an entitlement to payment, compensation or other reward.
12. Regulatory Notifications
Tex Automation assesses reported vulnerabilities and security incidents to determine whether notification obligations under Article 14 of Regulation (EU) 2024/2847 (Cyber Resilience Act) or other applicable law are triggered.
A report submitted under this policy is not automatically reportable to authorities. Where the applicable legal criteria are met, Tex Automation will make the required notifications through the designated reporting channels and within the applicable deadlines.
13. Confidentiality and personal data
Vulnerability reports will be handled on a need-to-know basis. Tex Automation will use information received to investigate, remediate, coordinate and document the reported issue, and to comply with applicable legal obligations.
Reporter identity will not normally be published without explicit consent, except where disclosure is required by law, a competent authority or a binding legal process. Reporters should avoid submitting personal data or confidential information that is not necessary for the vulnerability report.
14. Report outcomes and policy changes
Not every submitted report will result in a security update or public advisory, for example where the report is not reproducible, is a duplicate, is outside the scope of this policy or does not constitute a cybersecurity vulnerability.
This section does not limit Tex Automation’s obligation to address and remediate confirmed vulnerabilities and to disclose information about fixed vulnerabilities where required by applicable law.
Tex Automation may update this policy to reflect changes in products, processes, standards or applicable law.
15. Contact details
Legal entity |
Tex Computer s.r.l.
|
Address |
VIA OTTORINO RESPIGHI, 13 — 47841 CATTOLICA (RN), ITALY |
PSIRT email |
psirt@texautomation.it |
General website |
https://www.texautomation.it/ |
Languages |
ENGLISH / ITALIAN |