Coordinated Vulnerability Disclosure (CVD) Policy

We take the security of our products and the protection of our customers seriously. In accordance with the EU Cyber Resilience Act (CRA), we are committed to a transparent, responsible, and coordinated approach to handling security vulnerabilities.

If you have discovered a vulnerability in one of our products, we ask you to report it to us confidentially.


 

1. Current Software Support & Scope

The following table shows which product versions we are currently accepting and evaluating security reports for.

Product / ComponentVersionStatusExpected LifecycleSecurity Updates
WeinCAD.NET / Moineauv2022 - v2026🟢 Actively maintainedRegular product cycleOngoing security patches
WeinCAD.NET / Compressorv2026🟢 Actively maintainedRegular product cycleOngoing security patches
WeinCAD classic / Extruderv58.x (Current)🟡 LimitedUntil the release of WeinCAD.NET / ExtruderCritical security fixes only
WeinCAD classic / Extruderv32.x to v57.x🔴 End-of-LifeSupport endedNo further updates
WMDSv58.x (Current)🟡 LimitedUntil the release of WMDS.NETCritical security fixes only
WMDSv32.x to v57.x🔴 End-of-LifeSupport endedNo further updates

Note on CRA Compliance: Our internal update and documentation processes are currently being gradually adapted to guarantee full compliance with the requirements of the Cyber Resilience Act in time for the legal deadline on December 11, 2027, for all future product generations.


 

2. Service Level Agreements (SLA) & Response Times

We commit to adhering to standardized processing times upon receipt of a valid vulnerability report:

  • Acknowledgment of Receipt: Within 3 business days, you will receive confirmation that your report has been received by our security team.
  • Initial Validation (Triage): Within 7 business days, we will inform you whether the vulnerability could be reproduced and confirmed.
  • Status Updates: We will keep you informed about the current status of the remediation at least every 14 days.
  • Patch Deployment: We aim to resolve security risks within 90 days after triage via a free update before any details are published.

 

3. How to Report a Vulnerability

Please do not send any unencrypted details about vulnerabilities via standard email.

  1. Communication Channel: Send your report via email to security@weingartner.com.
  2. Encryption: You must use our PGP key to encrypt the report.
  3. Required Information:
    • Affected product and exact version number (see support table).
    • Type of vulnerability.
    • Step-by-step instructions for reproduction (Proof of Concept).
    • Potential impact on the system.

 

4. Rules for Security Researchers (Safe Harbor)

If you comply with this policy, we commit to not taking any legal action against you:

  • Do No Harm: Do not attempt to access or modify customer data, or cripple the system via Denial-of-Service (DoS).
  • Confidentiality (CVD): Do not disclose information about the vulnerability to third parties until we have released the patch or the agreed 90-day period has expired.
  • No Extortion: This process is intended to improve IT security. Reports tied to financial demands (extorting a Bug Bounty) violate this policy.

 

5. Regulatory Reporting Requirements (CRA Art. 14)

As a manufacturer, we would like to point out that we are legally obligated to report actively exploited vulnerabilities within 24 hours as an early warning to the relevant authorities (e.g., ENISA / national CSIRT). A final technical report will be provided within 72 hours. We work closely with the authorities to ensure the protection of the European market.