Product Security Incident Response Team (PSIRT)
Security is a central component of the ProductsDevelopment. The EU Cyber Resilience Act (CRA) and the Radio Equipment Directive (RED) establish binding standards for cybersecurity and security for networked digital devices. Products and radio equipment.
Our Product Security Incident Response Team (PSIRT) is responsible for receiving, analyzing, and resolving security vulnerabilities in embedded systems.Products affect.
We rely on close and trusting cooperation with security researchers, customers and partners.
What product safety incidents can you report here?
The following cases are product safety incidents:

Security incidents in our hardware such as
- System on modules
- Single Board Computers
- OEMProducts
- Embedded vision solutions
- Low power solutions

Errors in our documentation regarding
- Safety
- Recommendations for action

Unauthorized publication
- from safety-critical PHYTEC documents
- security-relevant information about PHYTEC
Is your problem not listed? For general product issues, please contact our Help Desk.
What are your next steps?
If you believe you have discovered a security vulnerability in a PHYTEC product, please report it to us responsibly.
We need some information from you to quickly provide you with a solution. We will treat the information you provide confidentially and use it solely for the purpose of resolving your issue. We will only share this information if legally required to do so.
We need at least the necessary informationWithout them, we cannot fully process your report:
Necessary information
- Description of the vulnerability
- Date and time of discovery
- Affected product(s) and version(s)
- Operating system of the affected component(s)
- Step-by-step instructions for reproduction
Additional Information
- Proof-of-concept or exploit code (if available)
- List any third parties involved (if possible)
- Initial assessment of the impact
Here's how you can contact us safely and quickly:
Email: psirt@phytec.de
Use our PGP key to encrypt your message: https://openpgpkey.phytec.de/.well-known/openpgpkey/phytec-de-eu-psirt_public.asc
Fingerprint of the PHYTEC PSIRT PGP Key: 5A2B757E69748EFDAD4433D2C916C1DC561BA882
Here you can obtain the necessary software:
GnuPG (free)
Frequently Asked Questions
We assess vulnerabilities using the Common Vulnerability Scoring System (CVSS). The CVSS score indicates the severity of a vulnerability on a scale from 0,1 to 10,0.
- Critical: 9,0–10,0
- High: 7,0–8,9
- Average: 4,0–6,9
- Low: 0,1–3,9
More information about CVSS can be found here: https://www.first.org/cvss/calculator/4.0
PHYTEC publishes security advisories for confirmed vulnerabilities. These contain key information for assessing and remediating the vulnerability, including:
- Description of the vulnerability
- affected Products
- Severity classification
- available fixes or workarounds
- CVE references, if available
Security-related updates are provided via software releases or BSP updates, firmware updates, and direct customer information, depending on the product.
We generally recommend using the latest supported version.