Coordinated Vulnerability Disclosure (CVD) Policy

This policy explains how we receive, evaluate, remediate, and coordinate the disclosure of product security vulnerabilities, as well as the principles that reporters should follow during the research and submission process.

Introduction

We are committed to providing our customers with the information, guidance, and mitigation strategies they need to address product security vulnerabilities in a timely manner. The Product Security Incident Response Team is responsible for coordinating vulnerability response and disclosure, and for advising customers to migrate to supported product versions before the end of the support period.

Handling Vulnerability Reports

Information regarding newly disclosed vulnerabilities should be treated as confidential until it is made public. Once verification is complete, we will coordinate with the product team, third-party vendors, and the reporting party to develop a fix or mitigation plan.

Bug Fixes

Severity and Impact Assessment

Severity LevelCVSS Base Score
Serious9.0–10.0
高7.0–8.9
中4.0–6.9
低0.1–3.9

External Communication

We provide details on the impact, affected products and versions, CVE/CVSS information, mitigation measures, and necessary reference materials through security advisories, notifications, and informational articles.

How to Report a Security Vulnerability

Disclaimer

This policy is subject to change based on changes in laws, standards, products, and business operations. Specific customer rights are governed by the applicable contracts, warranties, and support agreements.