noindex nofollow
本文にスキップする

Select your region & language

Global

Region

Product Vulnerability Contact (ONO SOKKI PSIRT)

Basic principles and commitments

Ono Sokki Co., Ltd. prioritizes the security of measurement and control equipment and related software, as well as the safety of its customers. We recognize that continuous risk assessment and countermeasures against cyber threats are critical issues in asset management for our customers. We practice collaborative vulnerability disclosure (CVD) and strive to ensure security throughout the entire product lifecycle.

How to report vulnerabilities and security incidents

 If you have information that contributes to improving the safety of the product, or information regarding cybersecurity incidents related to the product (such as suspicious behavior or suspected breaches),please report it to the PSIRT contact below.The information you provide will be used to correlate with specific vulnerability databases (such as CVE), identify the scope of impact on the product, and facilitate rapid incident response. For a smooth investigation, please cooperate by providing the following information as much as possible.

  • Product Information: Product name, model number, version number (necessary for identifying the component information that makes up the product)
  • Details of vulnerabilities or incidents: Specific circumstances of the discovered security weaknesses or incidents that occurred.
  • Reproduction Steps: Describe what actions lead to the issue (e.g., on which screen, what button was pressed, etc., detailing the specific sequence of operations and the environment in which it occurred.
  • Presence or absence of signs of exploitation: Information on whether there are any indications that the discovered vulnerability is "actually being exploited (attacked)" or if there is suspicion that damage has already occurred due to an incident.
  • Contact of the reporter: If you wish to receive feedback on the investigation status

ONO SOKKI PSIRT Contact Information

E-Mail: psirt

Response process to vulnerabilities

After receiving the report, we will proceed with the response according to the following timeline under the management of the Product Security Incident Response Team (PSIRT).

  • Receipt Confirmation: After receiving the report, a notification of completion will usually be sent within 5 business days.
  • Initial Report: After receiving the report, we will contact you with the results of the preliminary investigation (whether there is an impact from the vulnerability and an outline of future response policies, etc.) as the initial report within 10 business days.
  • Preparation of Investigation and Countermeasures: Identify products affected by vulnerabilities and conduct a severity assessment from both "likelihood of occurrence" and "magnitude of loss/impact" using CVSS (Common Vulnerability Scoring System), and prepare remediation patches or workarounds. The goal is usually to resolve within 90 days, but the duration may vary depending on the characteristics of the equipment and the verification process.

Regarding anonymous reports

We accept anonymous reports of vulnerabilities and incidents; however, in such cases, we cannot guarantee the response schedule (such as acknowledgment of receipt) as we have no means to request additional information or confirm the situation. Please be aware that if the information provided is insufficient for verification, our response may be limited or we may be unable to complete the response.

Disclosure of security information (Advisory)

As soon as the preparation of the fix or workaround is complete, we will promptly publish a security advisory based on the principle of transparency. The advisory will include the following information to help our customers take appropriate measures.

  • Detailed explanation of vulnerabilities.
  • Products and versions affected.
  • Severity assessment by CVSS
  • Specific correction and avoidance procedures that customers can easily understand and execute.

However, if there is a "legitimate reason" to determine that disclosing information before adequate measures are in place would actually increase the security risks for customers, we may prioritize customer protection and temporarily delay the release of that information.

Update date September 30, 2026