Product Security Incident Response Team (PSIRT)

  • CRA Compliance
  • Effective protection of your know-how and more
  • Protective availability of devices and services
  • Cybersecurity retrofitting for your field equipment

Security is a central component of the ProductsDevelopment. The EU Cyber ​​Resilience Act (CRA) and the Radio Equipment Directive (RED) establish binding standards for cybersecurity and security for networked digital devices. Products and radio equipment.

Our Product Security Incident Response Team (PSIRT) is responsible for receiving, analyzing, and resolving security vulnerabilities in embedded systems.Products affect.

We rely on close and trusting cooperation with security researchers, customers and partners.

What product safety incidents can you report here?

The following cases are product safety incidents:

Security incidents in our hardware such as

  • System on modules
  • Single Board Computers 
  • OEMProducts
  • Embedded vision solutions
  • Low power solutions

Errors in our documentation regarding

  • Safety
  • Recommendations for action

Unauthorized publication

  • from safety-critical PHYTEC documents
  • security-relevant information about PHYTEC

Is your problem not listed? For general product issues, please contact our Help Desk.

What are your next steps?

If you believe you have discovered a security vulnerability in a PHYTEC product, please report it to us responsibly.
We need some information from you to quickly provide you with a solution. We will treat the information you provide confidentially and use it solely for the purpose of resolving your issue. We will only share this information if legally required to do so.

We need at least the necessary informationWithout them, we cannot fully process your report:

Necessary information

  • Description of the vulnerability
  • Date and time of discovery
  • Affected product(s) and version(s)
  • Operating system of the affected component(s)
  • Step-by-step instructions for reproduction

Additional Information

  • Proof-of-concept or exploit code (if available)
  • List any third parties involved (if possible)
  • Initial assessment of the impact

Here's how you can contact us safely and quickly:

 Email: psirt@phytec.de

Use our PGP key to encrypt your message: https://openpgpkey.phytec.de/.well-known/openpgpkey/phytec-de-eu-psirt_public.asc

Fingerprint of the PHYTEC PSIRT PGP Key: 5A2B757E69748EFDAD4433D2C916C1DC561BA882

Here you can obtain the necessary software:
GnuPG (free)

Frequently Asked Questions

We assess vulnerabilities using the Common Vulnerability Scoring System (CVSS). The CVSS score indicates the severity of a vulnerability on a scale from 0,1 to 10,0.

  • Critical: 9,0–10,0
  • High: 7,0–8,9
  • Average: 4,0–6,9
  • Low: 0,1–3,9

More information about CVSS can be found here: https://www.first.org/cvss/calculator/4.0

PHYTEC publishes security advisories for confirmed vulnerabilities. These contain key information for assessing and remediating the vulnerability, including:

  • Description of the vulnerability
  • affected Products
  • Severity classification
  • available fixes or workarounds
  • CVE references, if available

Security-related updates are provided via software releases or BSP updates, firmware updates, and direct customer information, depending on the product.

We generally recommend using the latest supported version.