Product Security and Coordinated Vulnerability Disclosure 

DOVER EUROPE SÀRL (MARKEM-IMAJE)

 

Our Commitment to Product Security 

At Markem-Imaje cybersecurity is an integral part of how we design, develop, manufacture, deploy, and maintain our products. We are committed to protecting our customers, partners, and stakeholders by continuously improving the security and resilience of our products throughout their lifecycle.  

 We recognize the important role that customers, partners, security researchers and the broader security community play in identifying and responsibly reporting potential vulnerabilities. Our Coordinated Vulnerability Disclosure (CVD) process provides a clear and transparent mechanism for reporting security vulnerabilities and working collaboratively towards their timely resolution.  

 Our vulnerability management and disclosure practices are aligned with industry-recognized security principles and applicable regulatory requirements, including relevant obligations under the EU Cyber Resilience Act (CRA).  

Product Security and Coordinated Vulnerability Disclosure (CVD) Process 

Overview  

The Coordinated Vulnerability Disclosure process ensures that reported vulnerabilities are assessed, remediated, and communicated in a responsible and timely manner. 

 1. Vulnerability Submission 

A customer, security researcher, partner, supplier, or other stakeholder reports suspected security vulnerability through our designated reporting channels. 

2. Acknowledgement 

Our Product Security Incident Response Team (PSIRT) reviews the submission and acknowledges receipt of the report, typically within a reasonable timeframe. 

3. Triage and Validation 

The reported issue is assessed to determine: 

- Whether the issue represents a valid security vulnerability. 

- Affected products, software versions, firmware versions, or services. 

- Potential impact on confidentiality, integrity, availability, privacy, or safety. 

- Severity, exploitability, and customer impact. 

4. Investigation and Risk Assessment 

The Product security incident response team (PSIRT) coordinates with product engineering, software development, quality, compliance, and other stakeholders to investigate the issue, determine root cause, and assess risk. 

5. Remediation and Verification 

Appropriate remediation actions may include: 

- Software patches 

- Firmware updates 

- Security configuration changes 

- Mitigation guidance 

- Product documentation updates 

All corrective actions are validated before release. 

6. Customer Communication 

Where appropriate, customers are informed through security advisories, release notes, direct communications, or other approved communication channels. 

7. Coordinated Public Disclosure 

We support responsible and coordinated disclosure practices. Public disclosure should occur only after remediation or mitigation is available, or after an agreed disclosure timeline has been reached. 

8. Continuous Improvement 

Lessons and improvements from vulnerability investigations are incorporated into our secure development lifecycle, threat modeling activities, security testing programs, and product security governance processes. 

 

Scope 

This Coordinated Vulnerability Disclosure process applies to security vulnerabilities affecting products and services developed, maintained, or supported by Markem-Imaje. 

 In Scope include: 

- Hardware products designed, developed, or manufactured by Markem-Imaje. 

- Software applications and platforms developed by Markem-Imaje. 

- Embedded software and firmware components. 

- Product security vulnerabilities that may impact customers, partners, or business operations. 

 

Vulnerability Assessment Considerations 

Reported vulnerabilities may be evaluated based on: 

- Product and version affected 

- Ease of exploitation 

- Potential business impact 

- Potential customer impact 

- Safety implications 

- Privacy implications 

- Availability of mitigations 

- Regulatory and contractual obligations 

 

Reporting a Security Vulnerability 

We encourage responsible disclosure of suspected vulnerabilities affecting our products and services. 

 

Contact Information 

Product Security Incident Response Team (PSIRT) 

Email: productsecurity@ markem-Imaje.com 

PGP Public Key: [Link to PGP Key] 

Please use encrypted communication when sharing sensitive vulnerability information. 

 

Information to Include 

To assist with our investigation, please include: 

- Product name 

- Product version and configuration 

- Detailed vulnerability description 

- Reproduction steps 

- Screenshots, logs, packet captures, or proof-of-concept code (if available) 

- Potential impact assessment 

- Contact information for follow-up discussions 

 

What Happens After Submission? 

 Upon receiving your report: 

1. We acknowledge receipt of the submission. 

2. We assign a tracking reference. 

3. Our PSIRT performs initial triage and validation. 

4. Additional information may be requested if necessary. 

5. Risk and impact assessments are conducted. 

6. Remediation activities are coordinated with relevant teams. 

7. Security advisories and customer communications are prepared as required. 

8. Coordinated disclosure activities are managed with the reporter where applicable. 

 

Expectations for Security Researchers 

We welcome responsible security research and ask researchers to: 

- Act in good faith. 

- Avoid actions that may disrupt products, services, or customer operations. 

- Avoid accessing, modifying, deleting, or disclosing customer data. 

- Avoid privacy violations. 

- Refrain from publicly disclosing vulnerabilities before remediation or an agreed disclosure timeline. 

- Provide sufficient technical details to support validation and remediation. 

 

Researchers who act responsibly and in good faith in accordance with this policy will be treated as valued contributors to our security program. 

Product Security Incident Response Team (PSIRT) 

 

About Our PSIRT 

The Product Security Incident Response Team (PSIRT) is responsible for managing product security vulnerabilities throughout their lifecycle and coordinating vulnerability response activities across the organization. 

 

PSIRT Responsibilities 

The PSIRT is responsible for: 

- Receiving and tracking vulnerability reports. 

- Validating and prioritizing vulnerabilities. 

- Coordinating investigations and remediation activities. 

- Managing vulnerability communications and disclosures. 

- Publishing security advisories. 

- Supporting regulatory reporting obligations. 

- Driving continuous improvement in product security practices. 

 

Governance 

The PSIRT operates under the organization's Product Security Governance Framework and works closely with: 

- Product Engineering 

- Software Development 

- Product Safety and Compliance 

- Customer Support 

- Executive Leadership 

 

Vulnerabilities are prioritized using a risk-based approach considering exploitability, customer impact, safety implications, business impact, and applicable regulatory requirements. 

Security Advisories 

Security Advisory Program 

To promote transparency and customer awareness, Markem-Imaje publishes security advisories for confirmed vulnerabilities affecting our products and services. 

 

Advisory Information 

Security advisories may include: 

- Vulnerability identifier (e.g., CVE) 

- Affected products and versions 

- Vulnerability description 

- Severity assessment 

- Potential impact 

- Available patches or mitigations 

- Customer recommendations 

- Disclosure and publication dates 

 

Security Advisory Portal 

Published advisories, mitigation guidance, and remediation notices are available at: 

Security Advisory Portal: https://www. markem-Imaje.com/productsecurity/security-advisories 

 Customers are encouraged to review advisories regularly and implement recommended updates. 

 

Historical Advisories 

Historical advisories remain available to support customer risk management, compliance, and product lifecycle activities. 

Regulatory Compliance  

As part of our product security program, reported vulnerabilities may be assessed against applicable regulatory, legal, contractual, and industry obligations. 

 Where required, Markem-Imaje may notify relevant authorities, affected customers, distributors, partners, and other stakeholders regarding significant cybersecurity vulnerabilities or incidents in accordance with applicable laws and regulations, including the EU Cyber Resilience Act. 

 

Our objective is to ensure vulnerabilities are addressed in a timely, risk-based, and transparent manner while protecting customers and maintaining product resilience. 

Disclaimer 

This Coordinated Vulnerability Disclosure Policy is intended solely for reporting legitimate security vulnerabilities affecting products and services owned, developed, maintained, and supported by Markem-Imaje. 

 

By submitting a vulnerability report, you acknowledge that: 

- You have acted in good faith and in accordance with applicable laws and regulations. 

- You have not intentionally accessed, modified, destroyed, or disclosed data beyond what is necessary to demonstrate the vulnerability. 

- You have not conducted testing that negatively impacts confidentiality, integrity, availability, safety, or performance of products, services, or customer environments. 

- Submission of a vulnerability report does not create any entitlement to compensation, reward, public recognition, or contractual relationship unless explicitly agreed by Markem-Imaje. 

- Markem-Imaje reserves the right to determine vulnerability severity, remediation priorities, disclosure timelines, and communication methods. 

- Activities involving unlawful access, privacy violations, operational disruption, or malicious intent may be referred to appropriate authorities. 

- This policy does not authorize penetration testing, denial-of-service testing, social engineering, physical attacks, or any activity prohibited by law without prior written authorization. 

 

Any personal data submitted as part of a vulnerability report will be processed solely for the purposes of evaluating, investigating, remediating, and managing the reported vulnerability, as well as complying with applicable legal and regulatory obligations. Reporters should avoid including unnecessary personal data, confidential customer information, credentials, or production data unless strictly necessary to demonstrate the reported vulnerability. Any personal data received through this process will be processed in accordance with the Markem-Imaje Privacy Notice and retained only for as long as necessary for these purposes. While Markem-Imaje will review vulnerability reports submitted in good faith, it does not guarantee that every submission will result in remediation, acknowledgement, or further communication. Where applicable, personal data may be shared with other Markem-Imaje entities, Dover group companies, or service providers strictly involved in the investigation and remediation of the reported vulnerability, subject to appropriate confidentiality, security, and data protection safeguards. 

 

close
keyboard_arrow_up
rocket icon Quick Access Tools