PSIRT Vulnerability Management
Our policy is to follow a coordinated vulnerability disclosure process. This process allows independent parties that discover a vulnerability in a Vertiv product to disclose those concerns to Vertiv directly, giving us time to investigate and remediate before the vulnerability is disclosed publicly. This protects Vertiv’s customers while acknowledging the reporters’ efforts. If a reported vulnerability relates to a vendor product, the PSIRT will coordinate with the vendor to remediate the vulnerability. The PSIRT will communicate with the reporter throughout the vulnerability investigation and will provide mutually agreeable next steps.
PSIRT Vulnerability Management process
This process includes a simple intake process for external concerns about product security, robust monitoring of software components utilized in product development, quick understanding of scope and risk with discovered vulnerabilities, immediate connection to the right leaders for swift action, and consistent process for all items. The image below shows a high-level overview of the process. SLAs have been established with engineering teams in line with industry best practices
Reporting potential security vulnerability
Vertiv welcomes reports from independent researchers, industry organizers, vendors, customer and other sources concern with Product Security.
Find out more on
Coordinated Vulnerability Disclosure
Vertiv strongly believes in best practices and strives to follow Coordinated Vulnerability Disclosure (CVD). CVD is a process by which independent reporters, who discover a vulnerability in our products, can contact Vertiv directly and allow us the opportunity to investigate and remediate the vulnerability before the reporter discloses the information to the public.
Vertiv PSIRT then coordinates with the reporter throughout the vulnerability investigation and provides the reporter with updates on progress as appropriate. After an update or mitigation information is publicly released by Vertiv, the reporter is welcome to discuss the vulnerability publicly.
Following Vertiv’s CVD allows us to protect our customers and at the same time, coordinate public disclosures and appropriately acknowledge the reporter(s) for their finding.
Occasionally, Vertiv discovers security vulnerabilities in products from other vendors, and if this occurs then Vertiv follows its standard Coordinated Vulnerability Disclosure process and communicate the identified issue to the affected vendor or a third-party coordination Center.
Security risk assessment
Vertiv currently uses the Common Vulnerability Scoring System version 3.1 (CVSS v3.1) to evaluate the severity level of identified vulnerabilities. CVSS enables a common scoring method and a common language to communicate the characteristics and impacts of vulnerabilities. CVSS attempts to establish a measurement of how much concern a vulnerability warrant. The CVSS model uses three distinct measurements or scores that include Base, Temporal, and Environmental calculations, each consisting of a set of metrics. The full standard, which is maintained by the Forum of Incident Response and Security Teams (FIRST), can be found at CVSS SIG.
Vertiv follows CVSS v3.1 Specification Document Qualitative Severity Rating Scale Common Vulnerability Scoring System: Specification Document to define Severity Ratings as shown in the table below:
Security Impact Rating | CVSS Score |
Critical |
9.0 – 10.0 |
High |
7.0 – 8.9 |
Medium |
4.0 – 6.9 |
Low |
0.1 – 3.9 |
None |
0.0 |
Vertiv reserves the right to deviate from these guidelines in specific cases if additional factors are not properly captured in the CVSS score.
When and where applicable, Vertiv Security Bulletins will provide the CVSS v3.1 Base Score. Vertiv focuses on the Base metric group only, because it will bring the most value to our customers and represents the intrinsic characteristics of a vulnerability. Vertiv’s risk assessment is based on an average of risk across a diverse set of installed systems and may not represent the true risk of your local installation.
Vertiv recommends consulting a security or IT professional to evaluate the risk of your specific configuration and encourages you to compute the Environmental score based on your network parameters. Vertiv recommends that all customers consider the Base Score and any Temporal and/or Environmental Scores that may be relevant to their environment to assess their overall risk. This overall score represents a moment in time and is tailored to your specific environment. You should use a security or IT professional’s assessment of the issue and this final score to prioritize responses in your own environment.
Customer Rights: Warranties, Support and Maintenance
Vertiv customers’ rights with respect to warranties and support and maintenance, including vulnerabilities, in any Vertiv product are governed by the applicable agreement between Vertiv and each customer.
The statements on this web page do not modify or expand any customer rights or create any additional warranties. Any information provided to Vertiv regarding vulnerabilities in Vertiv products including all information in a product vulnerability report shall become the sole information of Vertiv.
Disclaimer
All aspects of Vertiv’s PSIRT process and policies are subject to change without notice and on a case-by-case basis. Response is not guaranteed for any specific issue or class of issues. Your use of the information on the document or materials linked from the document is at your own risk. Vertiv reserves the right to change or update this document without notice at any time.
All Vertiv information, design specifications, reference boards, files, drawings, diagnostics, lists, and other documents (together and separately, “materials”) are being provided “as is.” Vertiv makes no warranties, express, implied, statutory, or otherwise with respect to the materials, and all express or implied conditions, representations and warranties, including any implied warranty or condition of title, merchantability, satisfactory quality, fitness for a particular purpose and non-infringement, are hereby excluded to the maximum extent permitted by law.
Information is believed to be accurate and reliable at the time it is furnished. However, Vertiv Corporation assumes no responsibility for the consequences of use of such information or for any infringement of patents or other rights of third parties that may result from its use. No license is granted by implication or otherwise under any patent or patent rights of Vertiv Corporation. Specifications mentioned in this publication are subject to change without notice. This publication supersedes and replaces all information previously supplied. Vertiv Corporation products are not authorized for use as critical components in life support devices or systems without express written approval of Vertiv Corporation.