Opens in a new tab

Coordinated Vulnerability Disclosure Policy

ambihome by JUNG takes the security of its products seriously. We welcome reports from security researchers and work with you to remediate reported vulnerabilities responsibly.

Scope

This policy applies to the ambihome products with digital elements currently available on the market:

  • the ambihome Panel,
  • the ambihome control app,
  • the web visualisation (Web-Visu),
  • the CAD Tool,
  • the Pricefinder.

The scope will be extended as further ambihome products come to market.

Out of scope is hardware and are components from other manufacturers used in ambihome installations — for example KNX actuators and sensors (e.g. JUNG, MDT) or door stations (e.g. 2N, Doorbird). Please report vulnerabilities in those products directly to the manufacturer concerned.

Vulnerabilities in our internal IT (corporate and development systems) are handled through a separate channel (see “Reporting channels”).

Safe harbor

If you conduct your security research in good faith and in accordance with this policy:

  • we will consider your activities authorised,
  • we will not initiate or recommend legal action against you, nor pursue criminal proceedings,
  • and should a third party initiate legal action against you, we will make clear that your conduct was in line with this policy.

If at any point you are unsure whether a particular course of action is compatible with this policy, please contact us before you proceed. This commitment applies only for as long as you observe the rules and limits set out in this policy.

What to report (vulnerability guideline)

We are interested in security-relevant vulnerabilities that compromise the confidentiality, integrity or availability of our products — for example remote code execution, bypassing authentication or authorisation, injection vulnerabilities, insecure data processing, or the exposure of sensitive data.

Where possible, please include with your report: the affected product and version, a description of the vulnerability, reproducible step-by-step instructions (proof of concept), and an assessment of the potential impact.

Out of scope

In particular, we do not want:

  • denial-of-service attacks (DoS/DDoS) or tests that disrupt live operation
  • social engineering, phishing against employees, or physical attacks
  • reports based solely on automated scanners without a demonstrated, exploitable finding
  • purely theoretical vulnerabilities without a proof of concept
  • vulnerabilities that are already publicly known or have already been reported to us

Rules of conduct

Please use only your own test or demo accounts and do not access other users’ data. Avoid any disruption of live operation, do not modify or delete data, and do not expose more data than is necessary to demonstrate the vulnerability. Please publish details only after we have agreed on them together (see “Disclosure”).

Reporting channels

We recommend encrypted transmission via OpenPGP. You will find our public keys at https://ambihome.com/en/security. Reports in German and English are handled alike. Anonymous reports are possible via the web form.

Our commitments

  • You will receive an automatic acknowledgement with a reference number immediately.
  • We will normally provide an initial substantive response within 5 working days.
  • We will keep you informed of the status while we work on the report.
  • We assess every valid report, develop a solution and inform you of the outcome.

Disclosure

We follow a coordinated disclosure approach. Publication normally takes place within 90 days of the vulnerability being confirmed, agreed with you and once a fix is available. If a vulnerability is already being actively exploited, we act accordingly faster. The CVD process ends with the publication of a security advisory and the release of the fix — or, if no action is required, with a corresponding notification to you.

Responsible national CSIRT

ambihome is subject to the Cyber Resilience Act (Regulation (EU) 2024/2847). The responsible national CSIRT is CERT-Bund at the Federal Office for Information Security (BSI), reachable at certbund@bsi.bund.de.

Acknowledgement

On request, we will credit you as the reporter in our security advisory. We do not currently offer a paid bug bounty programme.