Cyber Resiliency Act (CRA)

Laser Diagnostic Instruments AS (LDI) is committed to maintain the security and privacy of our partners and clients. We recognize the importance of cyber security, aim to make our software and hardware products as safe as possible, and welcome any feedback that identifies security issues in our products.

The European Unions (EU) Coordinated Vulnerability Disclosure (CVD) policy (hereinafter, the “Policy”) applies to any vulnerabilities reported to LDI. This policy is based on the ETSI TR 103 838 standard. We appreciate and value those who take the time and effort to report security vulnerabilities under these Policy conditions. However, we do not offer rewards for vulnerability disclosures.

If you believe you have found a security vulnerability, please submit your report to us in the following email:

cra@ldi.ee

Please include in your report the following:

  • The asset where the vulnerability can be observed (name, model, software version, URL, etc.)
  • Weakness
  • Description of vulnerability (this should include a summary, supporting files and possible mitigations or recommendations)
  • Impact (what could an attacker do?)
  • Steps to reproduce this vulnerability

 

Our Response

LDI will first check and analyse the incoming report by our appropriate technicians. If we need further information, we will contact the reporting person. We will respond within 72 hours.

Solution

If the vulnerability requires a solution, we will work together with the department responsible for the product and, potentially other parties, to devise an appropriate solution. The solution to the reported vulnerability would be communicated to the reporter.

Disclosure

The vulnerability is disclosed at an agreed time. All required information, including the remedial measures taken, are disclosed then. Provided we have consent from the person who reported, he/she will be acknowledged on our website for their cooperation.

Contact

E-mail: cra@ldi.ee