RACOM Security Center

RACOM Vulnerability Disclosure and Security Update Policy

The purpose of this policy is to establish a framework for managing identified security vulnerabilities within RACOM products. It sets forth our objectives for notifying customers and deploying effective solutions.

Scope

This policy covers security vulnerabilities in our released and supported products. We define a security vulnerability as an unintentional weakness or flaw within hardware, firmware or software that has the potential to be exploited by a threat agent in order to compromise a customer’s network, including, but not limited to, unauthorised access, privilege escalation, information disclosure, or bypass of security controls.

This policy does not apply to general support, non-security defects, feature requests, incorrect installation, unsupported configurations, or customer-specific integration issues.

Introduction

RACOM products are designed to be secure and reliable elements of customers’ networks. RACOM products include many security features such as encryption, firewalls, authorization and authentication. RACOM’s development practices are intended to prevent the introduction of undocumented mechanisms that would intentionally bypass these security features. RACOM also monitors and assesses security risks arising from its own code, product design, integrated third-party components and publicly disclosed vulnerabilities.

RACOM welcomes the transparent reporting of vulnerabilities and is committed to resolving them in a timely manner. In addition to reporting by users, we actively search for vulnerabilities through internal testing, static code analysis, independent penetration testing and assessing new Common vulnerabilities and Exposure (CVE). These may be introduced through an error in design or development or through a vulnerability being discovered in third-party libraries integrated into our firmware or software. The vulnerabilities may be discovered through testing, reported as a Common Vulnerability and Exposure (CVE), or discovered by an independent security assessment or a customer.

Reporting a Potential Vulnerability, Assessment

RACOM promptly assesses the impact of any reported vulnerability to our products. Once the vulnerability is assessed by us or according to the Common Vulnerability Scoring System, details of the vulnerability, its impacts and timelines for resolution will be made publicly available to affected customers and partners.

RACOM  uses the Common Vulnerability Scoring System (CVSS 4.0) in combination with the severity ratings to evaluate newly reported potential vulnerabilities. The determined CVSS score reflects the potential security threat of the vulnerability within the context of our product design. RACOM security and development team reserves the right to internally re-classify the CVSS score to determine the likelihood of impact to RACOMproducts based on implementation differences.

Customers, partners, researchers and other parties who believe they have identified a security vulnerability in a RACOM product are encouraged to report it to:  vulnerability@racom.eu. Reports should include as much relevant information as reasonably possible.

Customer Communication

Customers and partners can register to receive information on potential vulnerabilities that are in process of being assessed or resolved through the RACOM Security Center. Any parties registered will receive Security Advisories on some Critical and High severity that will provide detailed information about the vulnerability. They will also receive updates on all issues they have reported regardless of type through our submission portal or through our support portal.

Vulnerability report signup

Do you want to receive updates on vulnerabilities?

* indicates required

I agree to receive information from RACOM. You can unsubscribe at any time by clicking on the link in the footer of our emails or at racom@racom.eu.

Information and Resolution Timelines

The CVSS score is used to prioritize and set targets for communication and resolution as follows:

Severity CVSS Resolution Target Fix Information
Critical 9.0–10.0 Patch release within 30 days after security advisory is posted Fix information is in the patch release notes.
High 7.0–8.9 Patch release within 30 days after security issue solved in third-party libraries   or within 60 days after  security advisory on our own code is posted Fix information is in the patch release notes.
Medium 4.0–6.9 Next release Release notes
Minor N/A Future release Release notes

Resolution of Vulnerabilities

RACOM takes security vulnerabilities seriously and uses commercially reasonable efforts to make resolution available to customers and partners in line with severity and risk profile of the vulnerability  for all supported products (to verify which products are no longer supported, please visit RACOM web pages).

For critical vulnerabilities, RACOM may activate its  formal Incident Management Process. This process involves dedicating appropriate resources to the resolution until a fix has been released. The process includes internal communication and escalation procedures to ensure the resolution receives the highest possible priority.

All software and firmware updates will normally be delivered through RACOM’s standard release channels.

Product Lifecycle and End of Support

Security updates are provided for RACOM products and versions that are within their defined support lifecycle. Customers may be required to upgrade to a current supported firmware or software version in order to receive or apply a security update.

When RACOM announces product End of Life (EOL), RACOM will define the applicable lifecycle milestones Unless RACOM states otherwise, software maintenance and security updates for an EOL product will be provided only until the applicable End of Software Release date,  or until the warranty expires, whichever comes later. 1 year past the Last Time Ship (LTS) date.

This includes commercially reasonable efforts to address deficiencies and update security features. Customers may be required to upgrade to a current version of firmware and/or implement other changes on the device to implement these updates.

Security vulnerabilities requiring changes to hardware design are extremely rare. For critical issues RACOM will issue a general recall for the affected devices. All other defects will be handled through the normal RMA process.

Questions?
Our Sales & Support team is ready!

©  2026 RACOM s.r.o. All Rights Reserved.