Affected product
Name the product, release, commit or service, including the relevant configuration.
Report vulnerabilities securely to the o6 Product Security Incident Response Team.
Please do not open a public issue or publish technical details before we have coordinated a response.
Send reports to either psirt@o6-automation.com or open62541-security@googlegroups.com. You can encrypt sensitive reports and attachments sent to either address with the same public key.
C969 F334 7BA6 31BD 5686 9514 AE55 28D6 D703 B17C
A useful report gives us enough context to reproduce the problem and understand its impact.
Name the product, release, commit or service, including the relevant configuration.
Describe what an attacker could achieve and which assumptions or access are required.
Provide clear steps, a minimal proof of concept, and relevant logs or traces.
Tell us whether anyone else knows, whether exploitation is suspected, and how you wish to be credited.
The response is coordinated around technical risk, affected users, and the availability of a safe mitigation.
We confirm receipt and establish a private channel for follow-up questions.
We reproduce the issue, assess severity, and determine affected products and versions.
We prepare and validate fixes or practical mitigations with the necessary maintainers.
We agree on publication timing and acknowledgement after users can protect their systems.
We value responsible research that avoids privacy violations, data destruction, service disruption, and unnecessary access to third-party systems. Please give us a reasonable opportunity to investigate and coordinate remediation before publication.
This channel is for potential security vulnerabilities. For product support, licensing, or general enquiries, please use our contact page.
Technical articles, release news, training dates, and company updates from o6 Automation.