Report a Security Vulnerability
If you believe you have found a security vulnerability in any AAEON product, we want to hear from you. Please report potential vulnerabilities directly to our product security team:
- Email: [email protected]
- Recommended Subject Format: <Vulnerability Report> <Product Name> - <Brief Description>
Our goal is to maintain transparency regarding potential vulnerabilities found in AAEON products and the corrective measures taken to address them, we kindly request that you do not publicly disclose the vulnerability until AAEON’s product security team has had the opportunity to investigate, verify, address, and fix the issue.
Information to Include in Your Report
To help us adequately investigate your report, please download and submit a completed Security Vulnerability Report Form with your email submission.
- Organization and contact name.
- Product model, Serial Number(s).
- Product Information (BIOS, OS, firmware, installed software, customized components).
- A detailed description of the vulnerability.
- Step-by-step instructions or scripts to reproduce the issue.
- If the incident is a known vulnerability, provide any available CVE ID, CWE ID, CVSS score/vector/version information.
Note: These details are requested to assist us in understanding, investigating, and working to resolve the issue identified. Being unable to provide comprehensive information for all of the above bullet points will not impact the priority with which we review your report. However, reports that do not include sufficient technical details or reproducible information may not be processed successfully.