PSIRT

I. About Renergy PSIRT
Renergy PSIRT (Product Security Incident Response Team) is a dedicated security response team established by Renergy to address security issues that may affect Renergy products, including security incidents and vulnerabilities.
Renergy places a high priority on product security and is committed to proactively identifying and addressing potential security vulnerabilities in its products. To support this commitment, Renergy has established a Product Security Incident Response Team and a comprehensive vulnerability response process covering vulnerability reporting, analysis, assessment, remediation, and resolution. This process helps ensure that security issues are addressed in a timely and effective manner.

II. Vulnerability Information Disclosure
Renergy will follow the "Coordinated Vulnerability Disclosure" (CVD) principle proposed by CERT (Computer Emergency Response Team) and publish security advisories for affected products. This serves three purposes: first, to ensure that vulnerabilities can be fixed and resolved in a timely manner; second, to minimize the security risk of vulnerability exploitation; and third, to provide users with sufficient information to help them accurately assess the risks faced by their own systems.
It should be noted that the security advisories published by Renergy are not a complete list of all security incidents. This is because we strictly follow the requirements of the CVD coordinated vulnerability disclosure specification and exercise appropriate control over the content and timing of disclosure. While safeguarding users' right to know, we also take into account the window time required for vulnerability remediation and the overall needs of security protection.

III. Reporting Vulnerabilities to Renergy PSIRT
If you discover potential security vulnerabilities in Renergy products, please send the relevant information to the Renergy PSIRT contact email

Email: psirt@renergy-me.cn


To facilitate the Renergy PSIRT in handling potential vulnerabilities, please provide the following information:

Renergy hardware/software product name, including the version or revision number

  • Detailed description of the vulnerability
  • Detailed description of potential vulnerability exploitation
  • Date the vulnerability was detected
  • Detailed information on how the vulnerability was discovered
  • How to confirm the potential vulnerability 

*Technical details (e.g., system configuration, trace files, description of exploit/attack code, sample packet captures)
*Software name/version used for confirmation (if required for confirmation)
*Any other items used for confirmation (if required for confirmation)

  • Any published public information (CVE, published academic papers, etc.)
  • Common Vulnerability Scoring System (CVSS) v3 score (if possible)

 

Your contact information 

  • Name
  • Organization and department name
  • Email address
  • Phone number

Important Notices:

  • Scope of Acceptance: We only accept information on potential vulnerabilities related to Renergy products. For other inquiries, please contact the Renergy switchboard at: +86-755-86221680.
  • Information Confidentiality: The contact information you provide will only be used for the analysis and recording of potential vulnerability information and will not be used for any other purposes.
  • Confidentiality Recommendation: To protect the security of all customers, we recommend that you do not disclose vulnerability information to any other individuals or organizations without prior consultation with Renergy PSIRT.
  • Disclosure Agreement: After you submit vulnerability information to Renergy, before Renergy reaches a formal conclusion, we may request that you temporarily refrain from publicly disclosing the vulnerability and not share it with any other individuals or organizations.
  • Response Time: We will make every effort to follow up on every piece of vulnerability information you submit. However, processing and response require a certain amount of time. Thank you for your understanding and patient cooperation.

IV. Renergy PSIRT Security Advisories
Please note that the security advisories published by Renergy are not intended to represent a complete record of all security incidents. In accordance with Coordinated Vulnerability Disclosure (CVD) principles, Renergy appropriately manages the scope and timing of disclosed information.