Report a Security Vulnerability

ARRI PSIRT encourages users and researchers to report security issues. The ARRI PSIRT encourages responsible disclosure of vulnerabilities with a view to the longer-term benefits they bring in terms of fixed vulnerabilities, better-informed customers, and continuous improvement of our security.

Please note that quality and warranty issues should be reported to your sales contact.

How to report a product security vulnerability?

If you believe that you have identified a potential security vulnerability or incident related to any ARRI product within its applicable support period, please contact us over psirt@arri.de.

What information should be submitted?

Please report the following information:

  • Affected product, including model and firmware version (if available).
  • Description of the vulnerability, including proof-of-concept, exploit code or network traces (if available). If a large amount of data needs to be submitted (more than 10 MB), we are able to offer an easy-to-use service for data transfer.
  • Public references, if there are any. Please indicate if the vulnerability has already been publicly disclosed and by whom.