Coordinated Vulnerability Disclosure Policy
1. Introduction
WEG is committed to the cybersecurity of its products, digital solutions and services. To continuously strengthen the security of our products, digital solutions and services, we encourage researchers, customers, partners, and other stakeholders to responsibly report vulnerabilities that may impact our products.
This Policy establishes the principles for the Coordinated Vulnerability Disclosure (CVD) process, promoting collaboration between WEG and the security research community, in line with international best practices and ISO/IEC 29147 and ISO/IEC 30111 standards.
2. Scope
This Policy applies to security vulnerabilities related to products, components, software, firmware, digital solutions and services developed, maintained or supported by WEG during their supported life cycle, as defined by WEG or required by applicable laws and regulations.
Questions related solely to technical support, customer-specific configurations, third-party products, or commercial solicitations are not part of this process.
When the reported vulnerability involves components, libraries, software, firmware, or services developed by third parties and incorporated into WEG products, the company may communicate the vulnerability to the respective suppliers, subject to the applicable contractual, legal and regulatory limitations. Responsibility for analyzing, developing, and making fixes available for these components remains with their respective vendors. WEG, however, may assess the impacts of the vulnerability on its products and may adopt the remediation, mitigation and communication measures that are technically feasible.
3. How to Report a Vulnerability
WEG provides official channels for receiving vulnerability reports.
Whenever possible, the report should include:
- affected product and version;
- description of the vulnerability;
- CVSS;
- CWE;
- steps to reproduce the vulnerability;
- relevant technical evidence;
- researcher contact information.
All reports are treated confidentially.
4. How We Treat Vulnerabilities
WEG will maintain internal processes for receiving, registering, classifying, evaluating, monitoring and addressing reported vulnerabilities related to products with digital elements covered by this Policy, in accordance with the applicable regulatory requirements.
After receiving the report, WEG carries out a structured process that may include:
1. Receipt and screening of the report;
2. Technical validation;
3. Impact and severity assessment;
4. Development of remediations, fixes, or mitigating measures, when applicable;
5. Communication with the researcher;
6. Coordinated disclosure where applicable.
WEG will seek to confirm the receipt of vulnerability reports within a reasonable period of time and may maintain communication with the researcher during the evaluation and treatment process, when it deems appropriate.
Treatment priority considers factors such as criticality of the vulnerability, potential impact, exploitability, and risks to customers and operations.
WEG will make reasonable efforts to analyze the reports received and define the measures it deems appropriate, in accordance with applicable technical, operational, legal and regulatory criteria. Nothing in this Policy shall be construed as guaranteeing remediation, mitigation, public disclosure or taking any specific action with respect to reported vulnerabilities. Decisions related to the assessment, prioritization, treatment, mitigation, correction and disclosure of vulnerabilities will be defined by WEG in accordance with technical, operational, legal, regulatory and risk management criteria applicable to each case.
5. Coordinated Disclosure
Our goal is to disclose information about vulnerabilities responsibly, balancing transparency and user protection.
Whenever possible, disclosure will occur after security updates, mitigating measures or appropriate guidance are made available to customers.
Communications may occur through:
- Security Advisories;
- technical bulletins;
- release notes;
- official communications.
In exceptional situations, including evidence of active exploitation or significant risks to users, WEG may adopt emergency communication and mitigation measures.
Coordinated disclosure will seek to avoid unnecessary exposure of personal data, confidential information, excessively exploitable details, or elements that may increase risks to customers, users, partners, or third parties.
WEG may share information related to vulnerabilities or incidents with competent authorities, regulatory bodies or other legally authorized entities, whenever there is a legal or regulatory obligation or valid applicable request, observing the principles of the LGPD, especially those of necessity, adequacy, security and limitation of sharing to the minimum necessary.
Vulnerabilities rated Low may be disclosed through the release notes or attachments to product security advisories. The release notes and security advisories will provide a succinct summary of the vulnerabilities that have been fixed, without disclosing detailed technical information that could facilitate their exploitation. As a rule, vulnerabilities classified as Low will not receive a CVE identifier, except when required by regulatory or contractual requirements or when WEG deems their attribution appropriate.
6. Safe Harbor
WEG recognizes the importance of security research conducted in good faith and does not intend to adopt legal measures against researchers who act ethically, responsibly and in accordance with this Policy, as long as they use the official communication channels and respect the limits established herein.
We expect researchers to:
- act responsibly;
- preserve the confidentiality of the information;
- avoid impacts on customers and operating environments;
- not disclose vulnerabilities prior to coordination with WEG;
- cooperate during the treatment process.
WEG will seek to conduct the coordinated disclosure process within a time frame compatible with the complexity of the vulnerability. Prior to the public disclosure of technical information related to the vulnerability, it is expected that the researcher will grant WEG a reasonable opportunity to evaluate and implement the measures deemed appropriate.
This protection does not apply to malicious activities, unauthorized access, service interruptions, social engineering, extortion, and/or any illegal conduct, such as access to personal data, confidential information, or intellectual property beyond what is strictly necessary to demonstrate
the vulnerability. This provision does not constitute unrestricted authorization for access to WEG's systems, data or environments and does not exclude the application of current legislation.
WEG considers "confidential information" to be all information and materials, whether oral, visual or tangible, including but not limited to (a) all developments; (b) all computer programs, documentation, financial, business and customer information, and other information; (c) all information of technological content (d) commercial and administrative methods, engineering, know-how, trade secrets, instruction manuals, financial statements and reports, strategic and business plans, market analysis and information, information about customers and suppliers; (e) all technical information about vulnerabilities, proofs of concept, exploitation methods, and remediation details, and (f) any other material or information that, or is marked as confidential or is reasonably assumed to be confidential and that should be protected and shared only with authorized parties during the review and handling process. Confidential Information may be characterized orally, visually, in writing and/or through graphics or computer databases, as well as any derivations.
7. Recognition
WEG recognizes the contribution of the research community to strengthening the security of its products.
When appropriate and with the consent of the researcher, WEG may acknowledge the contribution publicly in communications or other institutional channels.
Unless expressly stated by WEG otherwise, the submission of vulnerability reports does not generate any right to financial compensation, reward, remuneration, reimbursement or economic benefit of any nature.
8. Compliance
This Policy is aligned with international best practices for coordinated disclosure of vulnerabilities, including:
- IEC 62443-4-1: practices for secure development and handling of vulnerabilities in products;
- ISO/IEC 29147: guidance for coordinated disclosure of vulnerabilities;
- ISO/IEC 30111: guidance for managing and handling reported vulnerabilities;
- Cyber Resilience Act (CRA): regulatory requirements applicable to the management and disclosure of vulnerabilities in products with digital elements marketed in the European Union, where applicable;
- GDPR (General Data Protection Regulation): requirements for the protection of personal data, adoption of security measures, and handling of incidents involving personal data;
- LGPD (General Law for the Protection of Personal Data – Law No. 13,709/2018): requirements applicable to the protection of personal data, the adoption of security measures, and the assessment of incidents and vulnerabilities that may impact personal data, when applicable;
- Other applicable legal, regulatory and contractual requirements.
9. Contact
Vulnerabilities must be reported exclusively through the official channels made available by WEG. Product Security Incident Response Team (PSIRT) Email: psirt@weg.net PGP Key: Download public key Fingerprint: 75E2BD5DE29B847B6B7DAC3F9D3F749901D79A38
10. Updates to this Policy
WEG may revise this Policy from time to time to reflect changes in its processes, regulatory requirements or best cybersecurity practices.
11. Revision History
| Version | Date | Description |
|---|---|---|
| 1.0 | 19/08/2026 | Initial issuance of the Coordinated Vulnerability Disclosure Policy. |