Skip to content
Avolites
  • Lighting
  • Media
  • Software
  • Academy
  • #Avo50
  • News
  • Support
  • Contact Us

Product Security Incident Reporting (PSIR)

Welcome to the Avolites PSIR portal, your central hub for reporting security vulnerabilities and staying informed about our latest security measures. We are dedicated to protecting our users and systems through transparent communication and swift action.

 

Product Security Incident Report

Avolites acknowledges the requirements of the Cyber Resilience Act (CRA), based on Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024, and takes cybersecurity seriously across its products, services, and internal operations. This includes proactive prevention, as well as the identification and handling of cybersecurity incidents.

To support this commitment and meet regulatory requirements, Avolites operates a Product Security Incident Response Team responsible for overseeing reported incidents and vulnerabilities, including intake, assessment, response coordination, and follow-up actions.

 

What should be reported?

The following cybersecurity vulnerabilities are considered in scope:

    1. Unauthorized control of a device, including device control takeover via crafted packets
    2. Unexpected unencrypted or weakly encrypted communication, including authentication or encryption bypasses
    3. A vulnerability allowing execution of arbitrary code, including remote code execution via crafted packets
    4. A vulnerability allowing leakage of sensitive data
    5. Insecure update mechanism that could allow unauthorized or malicious updates
    6. Memory corruption or denial of service via crafted packets

The following incidents are considered out of scope:

    1. Physical access attacks
    2. General best practice suggestions without a demonstrated attack path

 

How to report an incident

Please report the security incident immediately using the form on this page. Information about the incident must not be disclosed, published, or shared elsewhere until the incident has been resolved.

When reporting a security incident, please include the following information:

    • Product details
      • Product name
      • Serial number
      • Last known software/firmware version installed on the device
    • Incident description – Please describe the incident in as much detail as possible and include supporting materials, if available (e.g., screenshots or videos)
      • When the incident occurred
      • Where the incident occurred
      • How the product was used or connected
      • How the incident or threat manifested, e.g., loss of device control or data leakage
      • What an attacker can do, including the potential impact and the conditions required
      • A minimal reproduction case or proof-of-concept, if available
      • Whether you believe the incident is remotely exploitable

Our Product Security Incident Response Team will review the associated risk and, if required, the incident may be reported to ENISA (the European Network and Information Security Agency). You will be contacted with information about the next steps.

Thank you for your help in keeping us safe.

To provide attachments of unsupported filetypes, please include details of the attachments within the ‘Incident description’.
The Product Security Incident Response Team will provide you with a secure method of sharing those files.

 

Recent Security Advisories

There are currently no security advisories.

Avolites

Site Links

  • Lighting
  • Media
  • Software
  • Academy
  • Newsletter signup
  • #Avo50
  • Privacy Policy

Support Links

  • Support
  • Getting Started
  • Titan & Prism Manual
  • Tutorials & Guides
  • Frequently Asked Questions
  • Product Security Incident Reporting (PSIR)
  • Login Area
  • Contact Us

Connect with Us

  • Avolites Twitter
  • Avolites Facebook
  • Avolites Instagram
  • Avolites Youtube
Avolites
  • Lighting
  • Media
  • Software
  • Academy
  • #Avo50
  • News
  • Support
  • Contact Us
  • Support
  • Getting Started
  • Titan & Prism Manual
  • Tutorials & Guides
  • Frequently Asked Questions
  • Product Security Incident Reporting (PSIR)
  • Login Area
  • Contact Us

Connect with Us

  • Avolites Twitter
  • Avolites Facebook
  • Avolites Instagram
  • Avolites Youtube
This website uses cookies to improve your experience. Cookie settingsACCEPT
Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT