CRA Incident Reporting Procedure
Reference: Cyber Resilience Act (EU) 2024/2847 – Article 14
Report a vulnerability or cybersecurity incident
Rhoss is committed to ensuring the security, integrity and resilience of its products and services.
If you have identified a potential security vulnerability or cybersecurity weakness, or have observed an incident involving a Rhoss product, please report it to our Product Security Incident Response Team (PSIRT).
In accordance with the Cyber Resilience Act (CRA), our PSIRT team will assess the report and, if necessary, submit a notification to ENISA’s Single Reporting Platform (SRP) within the following timeframes:
• Early Warning (preliminary notification): within 24 hours of receipt
• Full notification: within 72 hours of receipt
The date and time this report is received constitute the legal starting point for calculating these deadlines
Contacts
Reports must be sent to:
security@rhoss.com
What to report
You can use this channel to report:
•Security vulnerabilities in Rhoss products.
•Suspected vulnerabilities requiring further investigation.
•Vulnerabilities that allow unauthorised access.
•Remote Code Execution (RCE) vulnerabilities.
•Cybersecurity incidents involving Rhoss products.
•Evidence that a vulnerability may be actively exploited.
•Any issue that may compromise the confidentiality, integrity or availability of the product.
Information to include in the report
To enable the report to be properly assessed and managed, please provide as much detail as possible.
1. Reporter details
Full name;
Company or organisation (if applicable);
Email address for correspondence;
Telephone number (optional);
Reporter’s role (customer, security researcher, supplier, partner or other).
EXAMPLE
Name: Mario Rossi
Company: XYZ Security
Email: mario.rossi@example.com
Role: Security researcher
2. Details of the affected product
Identify the product involved as precisely as possible.
Product name
Model
Hardware version
Firmware version
Software version
Use or installation context (if known)
EXAMPLE
Product: ABC supervisory control system
Model: XYZ-100
Firmware: 2.5.1
Software: 4.2.0
Environment: Installation at an end customer’s premises
3. Detailed description of the issue
Clearly describe:
the observed behaviour;
the expected behaviour;
the conditions required for the issue to occur;
the potential impact on the system.
EXAMPLE:
An authenticated user with limited privileges
can access features reserved for administrators
by manually changing the browser URL.
This gives the user access to the machine’s operating parameters.
4. Steps to reproduce the issue
Where possible, describe step by step how to reproduce the observed behaviour.
EXAMPLE:
1. Log in as a standard user.
2. Open the Dashboard page.
3. Add “/admin” to the URL.
4. Verify access to the administrative functions.
5. Impact assessment
Indicate the potential consequences of the issue.
If possible, also indicate whether the issue is:
locally exploitable;
remotely exploitable;
accessible via the Internet;
limited to the local network.
EXAMPLE:
unauthorised access;
configuration changes;
data exposure;
service disruption;
loss of product availability;
compromise of the physical security of the installation;
other significant impacts.
6. Evidence of exploitation
If known, specify whether:
the vulnerability has only been identified;
it has been verified through controlled testing;
there is evidence of actual exploitation;
the exploit is publicly available (the code, tools or instructions required to exploit the vulnerability are publicly accessible).
EXAMPLE:
There is no known evidence of active exploitation.
The vulnerability has only been verified
in a laboratory environment.
7. Attachments and supporting material
If available, attach:
Screenshots
Log files
Network traffic captures (PCAP)
Demonstration videos
Relevant configurations
Proof of Concept (PoC)
Technical reports
8. Date of discovery
Indicate:
the date on which the issue was identified;
the date of any verification;
the date of this report.
Responsible Disclosure
Rhoss appreciates the contribution of researchers, customers and partners who report vulnerabilities in good faith.
We therefore ask you to observe the following:
Do not disrupt the operation of customers’ systems.
Do not access data without authorisation.
Do not modify or delete information.
Do not perform destructive testing.
Keep the information confidential until the analysis and mitigation activities have been completed.
Reports received will be handled in accordance with Rhoss’s internal PSIRT procedures.
What happens after submitting a report
After a report is received:
The report will be logged in Rhoss’s PSIRT process.
A preliminary assessment will be carried out.
Additional information may be requested.
The issue will be analysed and classified.
The need for any corrective action will be determined.
The notification obligations under the applicable legislation will be assessed.
The reporter may be contacted for updates or clarification.
Data confidentiality
Information submitted through this channel will be treated confidentially and used exclusively for:
vulnerability management;
cybersecurity incident response;
improving product security;
compliance with applicable regulatory obligations.
Thank you for your cooperation
Rhoss thanks its customers, partners, researchers and all stakeholders who contribute to the continuous improvement of product security by responsibly reporting vulnerabilities and cybersecurity incidents.
For all security reports:
security@rhoss.com
NOTE: This address must be used exclusively to report vulnerabilities and cybersecurity incidents. For sales enquiries, routine technical support or product information, please use the usual Rhoss contact channels.

