在 Silicon Labs,我们致力于与安全研究社区、客户及合作伙伴开展协作,以负责任的态度及时发现并解决漏洞。作为通用漏洞披露编号机构 (CNA),Silicon Labs 遵循漏洞披露与管理的行业规范,确保整个流程的透明度与问责性。
本常见问题页面旨在提供清晰指引,内容包括如何报告潜在安全问题、在披露流程中可预期的事项,以及我们如何处理漏洞披露。无论您是研究人员、开发人员还是客户,我们都十分感谢您为助力我们维护安全生态系统所付出的努力。
在 Silicon Labs,我们致力于与安全研究社区、客户及合作伙伴开展协作,以负责任的态度及时发现并解决漏洞。作为通用漏洞披露编号机构 (CNA),Silicon Labs 遵循漏洞披露与管理的行业规范,确保整个流程的透明度与问责性。
本常见问题页面旨在提供清晰指引,内容包括如何报告潜在安全问题、在披露流程中可预期的事项,以及我们如何处理漏洞披露。无论您是研究人员、开发人员还是客户,我们都十分感谢您为助力我们维护安全生态系统所付出的努力。
To report a product security vulnerability, please register and create an account at community.silabs.com and click on the "Vulnerability Disclosure" tab on the top right hand corner to select the "Vulnerability Report Submission" option in the drop down menu.
如需报告企业资产安全漏洞,请访问 community.silabs.com 注册并创建帐户,然后点击页面右上角的“漏洞披露”选项卡,在下拉菜单中选择“提交漏洞报告”选项。
请提供:
这有助于我们的 PSIRT 快速评估并处理问题。
Since registration involves an email address, and requires communication to address an issue, anonymity is likely going to be based on the information you provide at registration. In addition, the eligibility for our Bug Bounty Program will require some level of self-identification to be provided with directions on rewards.
The vulnerability is assessed based on several factors, which determine its priority. The approach to resolving the issue then follow and an advisory or disclosure is made for the vulnerability and fix, if applicable.
披露: 我们会发布安全公告,向已订阅的用户告知该漏洞信息。如需了解如何订阅安全公告通知,请点击此处。
是的,我们遵循协同漏洞披露原则。我们会与报告者合作,在公开披露前验证并修复漏洞,以更大限度降低对客户的风险。我们力求在发布安全公告的同时,提供可用的修复方案。在某些情况下,可能无法发布修复方案。
Researchers are welcome to reference the public security advisory and published CVEs in their communications or publications.
You can view previously published security advisories in our GitHub page.
You can sign up for email notifications when a new Security Advisory is published by Watching the security advisory GitHub repo. Note that a GitHub account is needed to watch GitHub repos. You will receive notifications whenever a new advisory is published. The filterable dashboard linked in the repo description can be used to determine if any of the advisories are relevant to your product(s).
是的,我们的漏洞赏金计划 (Bug Bounty Program) 会根据漏洞的严重程度和影响范围,为符合条件的漏洞提交提供奖励。See our Vulnerability Disclosure Program (VDP) FAQ for eligibility, scope, and reward details.
Qualifying vulnerabilities include those affecting our semiconductor products, firmware, or related software. 我们曾奖励过的部分常见漏洞类型包括:
Vulnerabilities discovered in our enterprise assets do not qualify for the bug bounty and are only part of the Vulnerability Disclosure Program. See our security vulnerability disclosure policy for more details.
Once you register as a researcher at community.silabs.com, and meet the requirements listed in the security vulnerability disclosure policy, you should be able to participate in the bug bounty program.
We only pay for confirmed vulnerabilities, that had not already been reported. Payments depend on the priority that Silicon Labs assigns to the vulnerability after internal review. The pricing of the bounty by priority is available in the Vulnerability Disclosure Program (VDP) FAQ.
To report an enterprise asset security vulnerability, please register as a researcher at community.silabs.com and from there you will be able to submit vulnerability reports.
我们的产品安全事件响应团队 (PSIRT) 负责管理公司产品中安全漏洞的识别、评估与解决工作。我们会与研究人员、客户及合作伙伴协作,以确保及时修复漏洞并开展透明沟通。
我们结合行业标准与内部评估来确定漏洞修复的优先级。We utilize the Common Vulnerability Scoring System (CVSS) 4.0, as well as other internal criteria, which enables us to assess the severity of each issue. 严重漏洞享有至高优先级,我们致力于在 90 天内完成其披露与修复工作。
是的,我们是 CNA(通用漏洞披露编号机构)。这让我们能够在适当时机为已确认的漏洞分配 CVE 编号,从而促进安全问题的公开披露。我们会在每份安全公告中包含相关的 CVE 编号。
我们高度重视数据隐私保护。漏洞报告会被保密处理、安全存储,且仅与参与漏洞修复的团队成员共享。
请选择至少一列。
