Here's how THA_innos reports vulnerabilities

Security issues in products and systems should be addressed promptly. If the Institute for Innovative Security (THA_innos) identifies a vulnerability, it discloses it through a responsible process, also known as “responsible disclosure.”

THA_innos Vulnerability Disclosure Policy

If the institute identifies one or more vulnerabilities, it contacts the affected company via email. If this email goes unanswered, another attempt to contact the company is made within seven calendar days. 

The affected company will be informed of the vulnerabilities discovered in its products and systems via a vulnerability report. This report contains information about the vulnerabilities, their exploitability, and an initial assessment of the criticality of the security issue.

THA_innos is available to answer companies’ questions throughout the entire process of addressing the vulnerability. In addition, the institute expects regular updates on the current status of the issue.

How to Handle the Report

THA_innos wishes to be credited as the discoverer of the vulnerability in connection with the security issue and insists on the vulnerability being publicly disclosed at the end of the disclosure process, for example via CVE (Common Vulnerabilities and Exposures) or through a publicly accessible security advisory.

Furthermore, THA_innos reserves the right to publish its own security advisory at the conclusion of the responsible disclosure process, which will describe the vulnerability in detail, as well as to provide proof-of-concept source code for the vulnerability, if applicable.

Disclosure of Information on Vulnerabilities

Should any of the following scenarios occur, THA_innos reserves the right to disclose information regarding the vulnerabilities.

  1. THA_innos receives no response—or no constructive response that contributes to resolving the vulnerability—to the submitted vulnerability report within 14 calendar days.
  2. The affected company does not provide users with a security patch or a security advisory to address the vulnerability within 90 calendar days. THA_innos may extend this deadline if the additional effort required to create and test a security update can be objectively justified and it is clear that the issue is being actively addressed.
  3. There is no regular communication of status updates during the responsible disclosure process.
  4. It turns out that the vulnerability is already being actively exploited in products or systems in the field. In this case, technical details regarding the vulnerability and possible mitigation measures will be published 7 calendar days after the initial contact with the company to enable affected users to respond promptly.

Vulnerabilities Discovered by THA_innos

E3/DC S10 Home Power Stations (see Release Notes 2022_04)Use of an untrusted domain in the speed testDominik Merli
CVE-2021-20868, CVE-2021-20869, CVE-2021-20870, CVE-2021-20871, CVE-2021-20872"Multiple vulnerabilities in KONICA MINOLTA MFPs and printing systems"Benjamin Kienle and Dominik Merli
Starke+Reichert Advisory (DMS-222, DMS-223, DMS-224, DMS-236)"Starke DMS"Benjamin Kienle and Dominik Merli
Advisory (ICSA-19-162-03)“Siemens LOGO!8 Devices”Christian Siemers and Irakli Edjibia
Advisory (ICSA-19-106-03)"PLC Cycle Time Influences"Matthias Niedermaier, Jan-Ole Malchow, and Florian Fischer
CVE-2019-10953“ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers”Matthias Niedermaier, Jan-Ole Malchow, and Florian Fischer
VDE-2018-013“WAGO 750-8xx Controller Denial of Service”Matthias Niedermaier, Jan-Ole Malchow, and Florian Fischer
VDE-2018-012“PHOENIX CONTACT ILC 1×1 ETH Denial of Service”Matthias Niedermaier, Jan-Ole Malchow, and Florian Fischer
Advisory (ICSA-17-264-04)“iniNet Solutions GmbH SCADA Web Server”Matthias Niedermaier and Florian Fischer
CVE-2017-13995“iniNet Solutions iniNet Web Server – Improper Authentication”Matthias Niedermaier and Florian Fischer
Advisory (ICSA-16-313-01)“Phoenix Contact ILC PLC Authentication Vulnerabilities”Matthias Niedermaier and Michael Kapfer
CVE-2016-8366“Phoenix Contact ILC PLCs—Credentials Management Errors”Matthias Niedermaier and Michael Kapfer
CVE-2016-8371“Phoenix Contact ILC PLCs - Improper Authentication”Matthias Niedermaier and Michael Kapfer
CVE-2016-8380“Phoenix Contact ILC PLCs - Access to Critical Private Variable via Public Method”Matthias Niedermaier and Michael Kapfer

More about THA_innos

The Institute for Innovative Safety and Security at the Technical University of Applied Sciences Augsburg (THA_innos) helps organizations of all sizes operate safely and sustainably in an interconnected world. Through the institute’s innovative approaches, systems, products, and personnel become resilient to digital threats to the economy and society.