Vulnerability Disclosure Procedure

Responsible Vulnerability Disclosure

At Konecranes, the security of our products, services and systems is a top priority. We are prepared to work in good faith with individuals who acting responsibly and legally report vulnerabilities according to this procedure. 

This Coordinated Vulnerability Disclosure Procedure outlines guidelines and our commitment for responsible vulnerability disclosure. It is intended for individuals conducting security research on Konecranes’ products, services, and environments.  

 

Scope

We openly accept vulnerability reports regarding the following:   

  • All Konecranes and Konecranes-owned brand products, including both hardware and software   
  • All internet facing Konecranes systems, including:   
    • the entire Konecranes’ web presence   
      • *.konecranes.com/*   
    • public IPs advertised under AS3215, and attached services   
  • All internet-facing systems under Konecranes-owned brands, including:   
    • the entire Demag web presence 
      • *.demagcranes.com/   
    • the entire Donati Cranes web presence 
      • *.donaticranes.com/ 
    • the entire R&M Materials Handling web presence 
      • *.rmhoist.com/ 
    • the entire SWF Krantechnik web presence 
      • *.swfkrantechnik.com/ 
    • the entire Verlinde web presence 
      • *.verlinde.com/ 
    • the entire TBA web presence 
      • *.tba.group/ 
      • *.tdo-qa.com/ 
      • *.commtrac-test.co.uk/ 
      • *.commtrac-stg.co.uk/

         

Reporting a vulnerability 

Submit reports through our secure web form. Anonymous reports are accepted.  

 

What we would like to see from you  

  • To help us triage effectively, please provide:   
  • Where the vulnerability was found and its potential impact   
  • Step-by-step reproduction instructions (PoC, screenshots welcome)   
  • Written report in English, if possible. 

What you can expect from us  

  • If you provide contact information, we will:   
  • Acknowledge your report within 3 business days   
  • Confirm the issue and keep you informed of remediation progress   
  • Maintain an open dialogue throughout the process  

Publication  

  • Subject to Konecranes’ discretion, the advisories for confirmed vulnerabilities in our products after a fix or mitigation will be available as a part of release notes.   
  • We aim to resolve vulnerabilities within 90 days of the initial report. We will agree on a disclosure date with the reporter.   
  • If we cannot meet the deadline: We will communicate a revised timeline to the reporter before the original deadline expires.   
  • We currently do not acknowledge the reporter in the published advisories.   
  • Reporter may publish independently after the agreed disclosure date.  

 

Questions 

For questions or suggestions about this procedure, contact us through the reporting form.