Report a Security Vulnerability
ARRI PSIRT encourages users and researchers to report security issues. The ARRI PSIRT encourages responsible disclosure of vulnerabilities with a view to the longer-term benefits they bring in terms of fixed vulnerabilities, better-informed customers, and continuous improvement of our security.
Please note that quality and warranty issues should be reported to your sales contact.
How to report a product security vulnerability?
If you believe that you have identified a potential security vulnerability or incident related to any ARRI product within its applicable support period, please contact us over psirt@arri.de.
What information should be submitted?
Please report the following information:
- Affected product, including model and firmware version (if available).
- Description of the vulnerability, including proof-of-concept, exploit code or network traces (if available). If a large amount of data needs to be submitted (more than 10 MB), we are able to offer an easy-to-use service for data transfer.
- Public references, if there are any. Please indicate if the vulnerability has already been publicly disclosed and by whom.