Vulnerability Response and Handling Process

I. Core Principles

  1. Reduce Harm and Lower Risk — Minimize damage to customers
  2. Timely Response and Remediation — Take measures to mitigate vulnerabilities and provide prompt mitigation solutions
  3. Proactive Management — Build management systems and clarify responsibility boundaries
  4. Continuous Optimization — Follow industry standards and continuously improve processes
  5. Open Collaboration — Strengthen connections with supply chain and external security ecosystem

II. Vulnerability Handling Process

Vulnerability handling process diagram

1. Vulnerability Awareness

Accept and collect suspected vulnerabilities from multiple sources, including external security researcher reports, customer feedback, internal security testing, and third-party vulnerability database monitoring.

2. Verification & Assessment

Confirm validity and assess impact scope. Severity rating based on CVSS v3.1 scoring system:

Security Severity Rating (SSR)CVSS Score Range
CriticalCVSS 9.0-10.0
HighCVSS 7.0-8.9
MediumCVSS 4.0-6.9
LowCVSS 0.1-3.9
InformationalCVSS 0.0

Assessment Timeline: Critical and High vulnerabilities within 5 business days, Medium and Low vulnerabilities within 10 business days.

3. Vulnerability Patching

Develop security patches and provide temporary mitigation measures. Patches are released after internal validation.

Patching Timeline:

  • Critical vulnerabilities: Mitigation within 7 days, patch within 30 days
  • High vulnerabilities: Patch within 30 days
  • Medium vulnerabilities: Patch within 90 days
  • Low vulnerabilities: Fix in next planned release

4. Information Release

Timely disclose vulnerability information and remediation solutions to customers.

Publication Methods:

  • Security Advisory (SA): For Critical and High severity vulnerabilities, includes vulnerability details, impact scope, CVSS score, and remediation solutions
  • Security Notice (SN): For Informational issues and industry security incident responses
  • Release Note (RN): For Medium and Low severity vulnerabilities, released with version/patch

Coordinated Disclosure: Negotiate disclosure timeline with reporters, default 90 days after patch release, shortened to 7 days for actively exploited vulnerabilities.

5. Closed-loop Improvement

Continuously optimize based on customer feedback and handling experience:

  • Collect user feedback
  • Process efficiency assessment
  • Root cause analysis
  • Update security mechanisms and coding standards

III. Security Commitment

  • Support Duration: Provide at least 3 years of security update support from product release date.
  • Emergency Response: For High Profile vulnerabilities (CVSS ≥ 7.0 with widespread attention or active exploitation), publish security notice within 24 hours, provide mitigation within 7 days, release patch within 30 days.
  • Beyond Lifecycle Support: Even after End of Security Support, may still provide fixes for Critical vulnerabilities (CVSS ≥ 9.0) affecting large numbers of devices in use.

IV. Third-Party Software and Open-Source Components

Continuously monitor security status of third-party software and open-source components used in products. For third-party vulnerabilities meeting any of the following criteria (CVSS ≥ 4.0, widespread attention, potentially or actively exploited), publish security notice within 24 hours of confirming impact.

V. Security Researcher Protection

  • Responsible Disclosure Protection: No legal action against good-faith security research activities; do not disclose reporter identity without consent.
  • Acknowledgment Mechanism: Public acknowledgment in security advisories (with reporter consent), display in official website security hall of fame.
  • Exclusions: Unauthorized access to customer data, service disruption, social engineering attacks, physical attacks, and activities violating local laws are not protected.

VI. Contact Us

Please fill out the form below. Our expert advisor will contact you shortly!
Inquiry:
Notes:
Cancel
Submit