Coordinated Vulnerability Disclosure (CVD) Policy
We take the security of our products and the protection of our customers seriously. In accordance with the EU Cyber Resilience Act (CRA), we are committed to a transparent, responsible, and coordinated approach to handling security vulnerabilities.
If you have discovered a vulnerability in one of our products, we ask you to report it to us confidentially.
1. Current Software Support & Scope
The following table shows which product versions we are currently accepting and evaluating security reports for.
| Product / Component | Version | Status | Expected Lifecycle | Security Updates |
|---|---|---|---|---|
| WeinCAD.NET / Moineau | v2022 - v2026 | 🟢 Actively maintained | Regular product cycle | Ongoing security patches |
| WeinCAD.NET / Compressor | v2026 | 🟢 Actively maintained | Regular product cycle | Ongoing security patches |
| WeinCAD classic / Extruder | v58.x (Current) | 🟡 Limited | Until the release of WeinCAD.NET / Extruder | Critical security fixes only |
| WeinCAD classic / Extruder | v32.x to v57.x | 🔴 End-of-Life | Support ended | No further updates |
| WMDS | v58.x (Current) | 🟡 Limited | Until the release of WMDS.NET | Critical security fixes only |
| WMDS | v32.x to v57.x | 🔴 End-of-Life | Support ended | No further updates |
Note on CRA Compliance: Our internal update and documentation processes are currently being gradually adapted to guarantee full compliance with the requirements of the Cyber Resilience Act in time for the legal deadline on December 11, 2027, for all future product generations.
2. Service Level Agreements (SLA) & Response Times
We commit to adhering to standardized processing times upon receipt of a valid vulnerability report:
- Acknowledgment of Receipt: Within 3 business days, you will receive confirmation that your report has been received by our security team.
- Initial Validation (Triage): Within 7 business days, we will inform you whether the vulnerability could be reproduced and confirmed.
- Status Updates: We will keep you informed about the current status of the remediation at least every 14 days.
- Patch Deployment: We aim to resolve security risks within 90 days after triage via a free update before any details are published.
3. How to Report a Vulnerability
Please do not send any unencrypted details about vulnerabilities via standard email.
- Communication Channel: Send your report via email to security@weingartner.com.
- Encryption: You must use our PGP key to encrypt the report.
- PGP Fingerprint: `14CA 7D78 3C8D D2E6 597C 0D04 AC3A 5836 BE25 3E34
- Link to the full Public Key: https://www.weingartner.com/PublicKeyCRAWeingartner.key
- Required Information:
- Affected product and exact version number (see support table).
- Type of vulnerability.
- Step-by-step instructions for reproduction (Proof of Concept).
- Potential impact on the system.
4. Rules for Security Researchers (Safe Harbor)
If you comply with this policy, we commit to not taking any legal action against you:
- Do No Harm: Do not attempt to access or modify customer data, or cripple the system via Denial-of-Service (DoS).
- Confidentiality (CVD): Do not disclose information about the vulnerability to third parties until we have released the patch or the agreed 90-day period has expired.
- No Extortion: This process is intended to improve IT security. Reports tied to financial demands (extorting a Bug Bounty) violate this policy.
5. Regulatory Reporting Requirements (CRA Art. 14)
As a manufacturer, we would like to point out that we are legally obligated to report actively exploited vulnerabilities within 24 hours as an early warning to the relevant authorities (e.g., ENISA / national CSIRT). A final technical report will be provided within 72 hours. We work closely with the authorities to ensure the protection of the European market.