Vulnerability Disclosure Policy

1. Purpose

Snom Technology GmbH ("Snom") is committed to maintaining the security of its products, services, and supporting infrastructure.

This Vulnerability Disclosure Policy (VDP), also referred to as a Coordinated Vulnerability Disclosure (CVD) Policy, explains how security researchers, customers, partners, and members of the public can responsibly report potential security vulnerabilities affecting Snom products and services.

Snom supports responsible security research and values reports that help improve the security and resilience of our products. We are committed to handling vulnerability reports in a transparent, consistent, and responsible manner and to protecting customers through appropriate remediation and communication processes.


2. Scope

This policy applies to potential vulnerabilities that may negatively impact:

  • Confidentiality
  • Integrity
  • Availability
  • Authenticity
  • Reliability
  • Non-repudiation
     

of Snom products with digital elements, including:

  • SIP desk phones
  • DECT systems
  • Conference phones
  • Software applications
  • Firmware
  • Cloud-based product services operated by Snom
  • Product management and provisioning services operated by Snom


3. Out of Scope

The following are generally outside the scope of this policy:

  • Third-party products, services, or infrastructure not owned or operated by Snom
  • Social engineering attacks
  • Phishing activities
  • Physical security attacks
  • Denial-of-Service (DoS) and Distributed Denial-of-Service (DDoS) testing
  • Vulnerabilities affecting products beyond their published End of Security Support date
  • Issues that have already been publicly disclosed and fully remediated

Third-party vulnerabilities should be reported to the respective vendor.


4. Principles of Responsible Disclosure

Snom supports Coordinated Vulnerability Disclosure based on the following principles:

  • Protecting customers and users from active threats
  • Providing timely security updates and remediation guidance
  • Maintaining transparent communication throughout the disclosure process
  • Collaborating responsibly with security researchers, customers, suppliers, and partners
  • Ensuring vulnerabilities are assessed and addressed according to their risk and impact
     

5. Product Security Incident Response Team (PSIRT)

The Snom Product Security Incident Response Team (PSIRT) is responsible for managing product security vulnerabilities.

The PSIRT is responsible for:

  • Receiving and acknowledging vulnerability reports
  • Triaging and validating reported vulnerabilities
  • Assessing severity and potential impact
  • Coordinating remediation activities
  • Managing communication with researchers and affected stakeholders
  • Publishing security advisories where appropriate
  • Supporting regulatory reporting obligations where required

 

6. Reporting a Vulnerability

Security vulnerabilities may be reported through the following channels:

The reporting channels above are intended exclusively for security-related reports.

 

7. Information to Include

To assist with investigation and remediation, please provide as much of the following information as possible:

  • Affected product name and model
  • Firmware or software version
  • Detailed description of the vulnerability
  • Potential impact and security implications
  • Step-by-step instructions for reproducing the issue
  • Supporting evidence, such as screenshots, packet captures, log files, or proof-of-concept code
  • Suggested severity assessment (optional)
  • Contact information for follow-up questions

Reports may be submitted anonymously; however, anonymity may limit our ability to investigate and provide status updates.

 

8. Expectations for Security Researchers

Researchers participating in responsible disclosure activities are expected to:

  • Act in good faith
  • Comply with applicable laws
  • Avoid privacy violations
  • Avoid accessing, altering, or deleting customer data
  • Avoid disrupting services or systems
  • Avoid denial-of-service testing
  • Avoid exploiting a vulnerability beyond what is reasonably necessary to verify its existence
  • Provide Snom with a reasonable opportunity to investigate and remediate the issue before public disclosure
  • Refrain from extortion or demands for payment
     

9. Safe Harbor

If security research is conducted in good faith and in accordance with this policy, Snom will consider such activities authorized.

Snom will not initiate legal action against individuals who:

  • Act in good faith
  • Comply with this policy
  • Avoid causing harm to customers, users, or systems
  • Do not intentionally access personal data
  • Do not act with malicious intent

If a third party initiates legal action relating to activities conducted in accordance with this policy, Snom may make it known that the activities were consistent with this policy.

 

10. Response Commitments

Snom is committed to timely and transparent communication.

  • Acknowledgement

We aim to acknowledge receipt of vulnerability reports within five (5) business days.

  • Initial Assessment

We aim to provide an initial assessment or request additional information within ten (10) business days.

  • Status Updates

For validated vulnerabilities under investigation, we aim to provide periodic status updates throughout the remediation process.

Response times may vary depending on the complexity and severity of the issue.

 

11. Vulnerability Handling Process

Snom operates a structured vulnerability handling process that includes:

  • Receipt and Validation
  • The reported issue is reviewed and assessed for completeness and reproducibility.
  • Analysis and Risk Assessment

The vulnerability is evaluated to determine:

  • Severity
  • Potential impact
  • Exploitability
  • Affected products and versions

Severity may be assessed using industry-recognized methodologies such as CVSS.

  • Remediation

When appropriate, Snom develops and tests:

  • Security patches
  • Firmware updates
  • Software updates
  • Mitigating measures
  • Verification

Remediation measures are verified before public release.

  • Disclosure

Where appropriate, Snom publishes Security Advisories containing information regarding affected products, remediation measures, mitigations, and update availability.

 

12. Coordinated Disclosure

Snom supports Coordinated Vulnerability Disclosure.

We request that researchers refrain from publicly disclosing vulnerabilities until:

Snom has investigated the issue;
Users have had a reasonable opportunity to deploy available mitigations or updates; or
A coordinated disclosure date has been agreed.

Snom reserves the right to disclose vulnerability information earlier where required to protect customers, address active exploitation, or comply with legal obligations.

 

13. Security Advisories

Where appropriate, Snom publishes Security Advisories through its Security Center.

Security Advisories may include:

  • Vulnerability description
  • Severity assessment
  • CVE references (where available)
  • Affected products and versions
  • Fixed versions
  • Mitigation measures
  • Security update information
  • Publication date
  • Revision history
  • Acknowledgement of reporting parties (with consent)
     

14. Security Updates and Support Periods

Snom provides security updates for supported products throughout their published security support period.

Current support periods are available in the Product Security Lifecycle section of the Security Center.

After a product reaches its published End of Security Support date, Snom may no longer provide security updates or remediation for newly discovered vulnerabilities.

 

15. Third-Party Components

Many Snom products incorporate third-party software components and open-source software.

When vulnerabilities affecting such components are identified, Snom assesses their impact on affected products and provides remediation, updates, or guidance where appropriate.

 

16. Regulatory Reporting

Where applicable, Snom fulfills regulatory reporting obligations concerning actively exploited vulnerabilities and security incidents in accordance with applicable legal requirements.

Such obligations may exist independently from the coordinated disclosure process described in this policy.

 

17. Confidentiality and Data Protection

Snom treats vulnerability reports confidentially and processes personal information in accordance with applicable privacy and data protection laws.

Reporter information will not be disclosed outside Snom without consent unless required by law.

 

18. Recognition

Snom does not currently operate a bug bounty program.

At Snom's discretion, researchers who responsibly disclose valid vulnerabilities may be acknowledged in public Security Advisories or other recognition programs, subject to their consent.

 

19. Policy Updates

This policy may be reviewed and updated periodically to reflect changes in products, security practices, legal requirements, and industry standards.

The latest version will always be published through the Snom Security Center.


Contact Information:

Product Security Incident Response Team (PSIRT)

Contact person

Headquarter Berlin

+49 30 - 39833-0
Office hours: Mo-Fr 9:00-17:00 (CET)

 

Inhouse Sales
Inhouse Sales

language Sales DACH

phone +49 30 39833 0

mail_outline website@snom.com

Locations

Snom Technology GmbH
Aroser Allee 66
13407 Berlin

Phone: +49 30 39833-0
Fax: +49 30 39833-111

info@snom.com
www.snom.com

Contact

Search for help

Are you looking for help with a problem, a manual, an answer to your question or the latest firmware for your Snom device?

We have set up the Snom Service Hub to provide you with everything you need.

 

 

Snom D865

Thank you for visiting the Snom website

Please choose the regional Snom website you would like to visit.


For the United States, Canada, Central and South America:

Snomamericas.com


For the Rest of the World:

snom.com