• Silicon Labs
  • 文档
  • 社区
Silicon Labs
  • ⟵ 返回
    产品
    2026 年技术讲座
    即刻开启深度学习之旅,收获前沿创想,获取专业指导,助您将下一个突破性成果更快推向市场。
    无线无线
    Amazon Sidewalk
    蓝牙
    LPWAN
    Matter
    多协议
    专有产品
    Thread
    Wi-Fi
    Wi-SUN
    Z-Wave
    Zigbee
    嵌入式硬件嵌入式硬件
    板和套件
    MCU
    电源管理
    传感器
    USB 桥接器
    无线模块
    无线 SoC
    物联网技术物联网技术
    信道探测
    能量收集
    机器学习
    安全
    服务服务
    定制零件制造
    开发人员服务
    SDK 延期维护服务
  • ⟵ 返回
    应用
    智能家居智能家居
    设备
    户外互联
    娱乐设备
    物联网网关
    LED 照明
    Residential Smart Energy
    安全摄像机
    传感器
    智能锁
    开关
    工业物联网工业物联网
    访问控制
    资产跟踪
    电池供电工具
    断路器
    商业照明
    电辅助计量
    应急照明
    工厂自动化
    人机界面
    Industrial Smart Energy
    工业可穿戴设备
    预测性维护
    流程自动化
    智能 HVAC
    智慧城市智慧城市
    电池存储
    电动汽车充电站
    智慧农业
    智能建筑
    智能计量
    智能太阳能光伏系统
    街道照明
    智能零售智能零售
    商业照明
    测向
    电子货架标签
    损失预防
    Wi-Fi 接入点
    互联健康互联健康
    便携式医疗设备
    智能医院
    智能可穿戴设备
  • ⟵ 返回
    软件与工具
    Simplicity Studio 6
    快速跟踪物联网开发
    软件和工具软件和工具
    Simplicity AI SDK
    软件开发套件 (SDK)
    SDK 发行说明
    软件参考文档
    软件开发工具
    硬件开发工具
    硬件文档
    GitHub 资源
    开发人员之旅开发人员之旅
    AI/ML
    Amazon Sidewalk
    蓝牙
    蓝牙网状网络
    Google Home
    Matter
    Simplicity SDK for Zephyr
    Wi-Fi
    服务服务
    定制零件制造
    开发人员服务
    SDK 延期维护服务
  • ⟵ 返回
    资源
    文档文档
    博客
    案例研究
    软件文件
    技术库
    白皮书
    培训培训
    2026 年技术讲座
    Works With 2025 点播
    网络研讨会
    课程
    合作伙伴合作伙伴
    渠道和分销
    生态系统合作伙伴
    合作伙伴网络
    服务服务
    定制零件制造
    开发人员服务
    SDK 延期维护服务
    支持支持
    社区
    提交工单
    质量与封装
    如何购买
    Vulnerability and Bug Bounty
    联系我们
  • ⟵ 返回
    公司
    关于我们公司关于我们公司
    社区承诺
    Silicon Labs 的包容性
    管理团队
    安全
    可持续性可持续性
    环境、社会和治理
    质量
    供应链责任
    新闻与活动新闻与活动
    博客
    新闻中心
    活动
    投资者关系投资者关系
    年度报告和代理
    董事会
    企业治理
    季度业绩
    SEC 备案
    招贤纳士招贤纳士
    海得拉巴办事处
    其他全球办事处
    联系我们
中文
  • English
  • English(英文)
  • 简体中文
  • 日本語
询问 AI
询问 AI
询问 AI
//
安全 // 安全漏洞常见问题

安全漏洞常见问题

在 Silicon Labs,我们致力于与安全研究社区、客户及合作伙伴开展协作,以负责任的态度及时发现并解决漏洞。作为通用漏洞披露编号机构 (CNA),Silicon Labs 遵循漏洞披露与管理的行业规范,确保整个流程的透明度与问责性。

本常见问题页面旨在提供清晰指引,内容包括如何报告潜在安全问题、在披露流程中可预期的事项,以及我们如何处理漏洞披露。无论您是研究人员、开发人员还是客户,我们都十分感谢您为助力我们维护安全生态系统所付出的努力。

报告漏洞

To report a product security vulnerability, please register and create an account at community.silabs.com and click on the "Vulnerability Disclosure" tab on the top right hand corner to select the "Vulnerability Report Submission" option in the drop down menu.

如需报告企业资产安全漏洞,请访问 community.silabs.com 注册并创建帐户,然后点击页面右上角的“漏洞披露”选项卡,在下拉菜单中选择“提交漏洞报告”选项。

请提供: 

  • 对漏洞的清晰描述。
  • 受影响的产品和版本。
  • 重现问题的步骤。
  • 潜在影响(例如数据泄露、系统受损)。
  • 任何概念验证代码或屏幕截图(如适用)。
  • 您的后续联系方式。
  • 如需署名,可提供署名信息。
  • For coding vulnerabilities, please point to the exact location of the vulnerable files.

这有助于我们的 PSIRT 快速评估并处理问题。

Since registration involves an email address, and requires communication to address an issue, anonymity is likely going to be based on the information you provide at registration. In addition, the eligibility for our Bug Bounty Program will require some level of self-identification to be provided with directions on rewards. 



披露流程

The vulnerability is assessed based on several factors, which determine its priority.  The approach to resolving the issue then follow and an advisory or disclosure is made for the vulnerability and fix, if applicable. 

披露: 我们会发布安全公告,向已订阅的用户告知该漏洞信息。如需了解如何订阅安全公告通知,请点击此处。

是的,我们遵循协同漏洞披露原则。我们会与报告者合作,在公开披露前验证并修复漏洞,以更大限度降低对客户的风险。我们力求在发布安全公告的同时,提供可用的修复方案。在某些情况下,可能无法发布修复方案。

Researchers are welcome to reference the public security advisory and published CVEs in their communications or publications.

You can view previously published security advisories in our GitHub page.

You can sign up for email notifications when a new Security Advisory is published by Watching the security advisory GitHub repo. Note that a GitHub account is needed to watch GitHub repos. You will receive notifications whenever a new advisory is published. The filterable dashboard linked in the repo description can be used to determine if any of the advisories are relevant to your product(s).



Bug Bounty Questions

是的,我们的漏洞赏金计划 (Bug Bounty Program) 会根据漏洞的严重程度和影响范围,为符合条件的漏洞提交提供奖励。See our Vulnerability Disclosure Program (VDP) FAQ for eligibility, scope, and reward details. 

Qualifying vulnerabilities include those affecting our semiconductor products, firmware, or related software. 我们曾奖励过的部分常见漏洞类型包括:

  • 内存破坏
  • 加密缺陷
  • 缓冲区溢出

Vulnerabilities discovered in our enterprise assets do not qualify for the bug bounty and are only part of the Vulnerability Disclosure Program. See our security vulnerability disclosure policy for more details.

Once you register as a researcher at community.silabs.com, and meet the requirements listed in the security vulnerability disclosure policy, you should be able to participate in the bug bounty program. 

We only pay for confirmed vulnerabilities, that had not already been reported. Payments depend on the priority that Silicon Labs assigns to the vulnerability after internal review.  The pricing of the bounty by priority is available in the Vulnerability Disclosure Program (VDP) FAQ.



企业相关问题

To report an enterprise asset security vulnerability, please register as a researcher at community.silabs.com and from there you will be able to submit vulnerability reports.



一般问题

我们的产品安全事件响应团队 (PSIRT) 负责管理公司产品中安全漏洞的识别、评估与解决工作。我们会与研究人员、客户及合作伙伴协作,以确保及时修复漏洞并开展透明沟通。

我们结合行业标准与内部评估来确定漏洞修复的优先级。We utilize the Common Vulnerability Scoring System (CVSS) 4.0, as well as other internal criteria, which enables us to assess the severity of each issue. 严重漏洞享有至高优先级,我们致力于在 90 天内完成其披露与修复工作。

是的,我们是 CNA(通用漏洞披露编号机构)。这让我们能够在适当时机为已确认的漏洞分配 CVE 编号,从而促进安全问题的公开披露。我们会在每份安全公告中包含相关的 CVE 编号。

我们高度重视数据隐私保护。漏洞报告会被保密处理、安全存储,且仅与参与漏洞修复的团队成员共享。

Silicon Labs

与我们保持联系

了解 Silicon Labs 产品的最新消息,包括产品发布和资源、文档更新、PCN 通知以及即将到来的活动等。

  • 公司简介
  • 招贤纳士
  • 社区
  • 联系我们
  • 企业责任
  • 投资者关系
  • 新闻发布室
  • 隐私条款
  • 网站反馈

联系我们:

Silicon Labs BiliBili 图标
Copyright Silicon Laboratories. 版权所有。
粤ICP备15107361号

您的文件将很快开始下载

谢谢您下载 。

如果您在下载中出现任何问题,请联系销售支持或产品技术支持。

关闭
正在加载结果
关闭

请选择至少一列。

Powered by Translations.com GlobalLink OneLink Software