Vulnerability Disclosure Policy
WatchGuard PSIRT
The WatchGuard Product Security Incident Response Team (PSIRT) is responsible for vulnerability and security incident management for issues involving WatchGuard products and services. PSIRT coordinates communications with third-party researchers and internal stakeholders throughout the vulnerability management process, from receipt and investigation through disclosure.
Report a Vulnerability to WatchGuard
Individuals and organizations can securely report a vulnerability to WatchGuard by following the detailed instructions on the Report a Vulnerability page.
After reviewing your report, a member of WatchGuard PSIRT will contact you to either ask for additional information or confirm the findings and start planning a coordinated disclosure.
Coordinated Disclosure Policy
WatchGuard believes in following a responsible disclosure process for potential security issues. We are committed to working with external security researchers to quickly and effectively identify, resolve, and disclose potential flaws.
As a CVE Certified Numbering Authority (CNA), we issue CVE identifiers and publish security advisories for all vulnerabilities that require user action to mitigate or resolve. For externally-reported vulnerabilities, we include the reporter's name (and/or social media handle when requested) in the published CVE and advisory on psirt.watchguard.com.
If you have identified a potential security issue, please report it to our product security team by following the instructions on the Report a Vulnerability page on psirt.watchguard.com. Please include as much detail in your report as possible to aid in confirming and resolving the issue (for example, reproducible steps or a working proof-of-concept).
To facilitate good-faith vulnerability research while protecting our customers, you should:
- Report any vulnerability you've discovered promptly, through the appropriate confidential communications channels.
- Keep your findings confidential until we have issued a remediation and our customers have had an appropriate amount of time to deploy it.
- Refrain from doing any harm — such as accessing accounts or private information owned by other users without explicit permission from the account holder and WatchGuard.
- Avoid any action that might cause a service disruption or violate the privacy of others or our terms of use.
Scope
This policy applies to all WatchGuard products and services.
Out of Scope
In the interest of our users' safety and privacy, the following test types and vulnerability locations are out of scope:
- Any issue derived from or involving social engineering of a WatchGuard employee, partner, or customer.
- General software bugs without a demonstrated security impact.
Safe Harbor
In return for your good-faith research abiding by our responsible disclosure process, we commit to:
- Not pursue any legal action related to your research; and
- Promptly work with you to understand and resolve the issue identified by your research.