Cyber Resilience Act

CRA Incident Reporting Procedure

 

Reference: Cyber Resilience Act (EU) 2024/2847 – Article 14

 

In this document, unless otherwise specified, all references shall be understood as referring to the Cyber Resilience Act (CRA), Regulation (EU) 2024/2847. Furthermore, the guidance provided herein is specifically intended for the purpose of creating and submitting the notifications and reports described within that Regulation.

 

Report a vulnerability or cybersecurity incident

Rhoss is committed to ensuring the security, integrity and resilience of its products and services.

If you have identified a potential security vulnerability or cybersecurity weakness, or have observed an incident involving a Rhoss product, please report it to our Product Security Incident Response Team (PSIRT).

 

In accordance with the Cyber Resilience Act (CRA), our PSIRT team will assess the report and, if necessary, submit a notification to ENISA’s Single Reporting Platform (SRP) within the following timeframes:

  • Early Warning (preliminary notification): within 24 hours of receipt
  • Full notification: within 72 hours of receipt

The date and time this report is received constitute the legal starting point for calculating these deadlines.

 

Contacts

Reports must be sent to:

security@rhoss.com

 

What to report

  • You can use this channel to report:
  • Security vulnerabilities in Rhoss products.
  • Suspected vulnerabilities requiring further investigation.
  • Vulnerabilities that allow unauthorised access.
  • Remote Code Execution (RCE) vulnerabilities.
  • Cybersecurity incidents involving Rhoss products.
  • Evidence that a vulnerability may be actively exploited.
  • Any issue that may compromise the confidentiality, integrity or availability of the product.

Information to include in the report

To enable the report to be properly assessed and managed, please provide as much detail as possible.

 

  1. Reporter details
  • Full name;
  • Company or organisation (if applicable);
  • Email address for correspondence;
  • Telephone number (optional);
  • Reporter’s role (customer, security researcher, supplier, partner or other).

 

EXAMPLE           

                Name: Mario Rossi

                Company: XYZ Security

                Email: mario.rossi@example.com

                Role: Security researcher

 

  1. Details of the affected product

Identify the product involved as precisely as possible.

 

  • Product name
  • Model
  • Hardware version
  • Firmware version
  • Software version
  • Use or installation context (if known)

 

EXAMPLE           

                Product: ABC supervisory control system

                Model: XYZ-100

                Firmware: 2.5.1

                Software: 4.2.0

                Environment: Installation at an end customer’s premises

 

  1. Detailed description of the issue

Clearly describe:

  • the observed behaviour;
  • the expected behaviour;
  • the conditions required for the issue to occur;
  • the potential impact on the system.

                                                              

EXAMPLE:          

                An authenticated user with limited privileges

                can access features reserved for administrators

                by manually changing the browser URL.

                This gives the user access to the machine’s operating parameters.

 

  1. Steps to reproduce the issue

Where possible, describe step by step how to reproduce the observed behaviour.

EXAMPLE:

  1. Log in as a standard user.
  2. Open the Dashboard page.
  3. Add “/admin” to the URL.
  4. Verify access to the administrative functions.

 

  1. Impact assessment

Indicate the potential consequences of the issue.

If possible, also indicate whether the issue is:

  • locally exploitable;
  • remotely exploitable;
  • accessible via the Internet;
  • limited to the local network.

 

EXAMPLE:          

                unauthorised access;

                configuration changes;

                data exposure;

                service disruption;

                loss of product availability;

                compromise of the physical security of the installation;

                other significant impacts.

 

  1. Evidence of exploitation

If known, specify whether:

  • the vulnerability has only been identified;
  • it has been verified through controlled testing;
  • there is evidence of actual exploitation;
  • the exploit is publicly available (the code, tools or instructions required to exploit the vulnerability are publicly accessible).

 

EXAMPLE:          

                There is no known evidence of active exploitation.

                The vulnerability has only been verified

                in a laboratory environment.

 

  1. Attachments and supporting material

If available, attach:

  • Screenshots
  • Log files
  • Network traffic captures (PCAP)
  • Demonstration videos
  • Relevant configurations
  • Proof of Concept (PoC)
  • Technical reports

 

  1. Date of discovery

Indicate:

  • the date on which the issue was identified;
  • the date of any verification;
  • the date of this report.

 

Responsible Disclosure

Rhoss appreciates the contribution of researchers, customers and partners who report vulnerabilities in good faith.

We therefore ask you to observe the following:

Do not disrupt the operation of customers’ systems.

Do not access data without authorisation.

Do not modify or delete information.

Do not perform destructive testing.

Keep the information confidential until the analysis and mitigation activities have been completed.

Reports received will be handled in accordance with Rhoss’s internal PSIRT procedures.

 

What happens after submitting a report

After a report is received:

The report will be logged in Rhoss’s PSIRT process.

A preliminary assessment will be carried out.

Additional information may be requested.

The issue will be analysed and classified.

The need for any corrective action will be determined.

The notification obligations under the applicable legislation will be assessed.

The reporter may be contacted for updates or clarification.

 

Data confidentiality

Information submitted through this channel will be treated confidentially and used exclusively for:

vulnerability management;

cybersecurity incident response;

improving product security;

compliance with applicable regulatory obligations.

 

Thank you for your cooperation

 

Rhoss thanks its customers, partners, researchers and all stakeholders who contribute to the continuous improvement of product security by responsibly reporting vulnerabilities and cybersecurity incidents.

For all security reports:

 

security@rhoss.com

 

NOTE: This address must be used exclusively to report vulnerabilities and cybersecurity incidents. For sales enquiries, routine technical support or product information, please use the usual Rhoss contact channels.