Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

The vendor and any other participant in the case will only be able to see the display name you choose when you create the VINCE account. This name can be changed at any time from within the in Profile page.

What happens to reports submitted anonymously (i.e., without being linked to a VINCE account)?

...

If a vendor is unresponsive, CERT/CC will attempt to elicit participation from the vendor, but CERT/CC can coordinate disclosure and publish a Vulnerability Note vulnerability note without the vendor's involvement.

...

If CERT/CC accepts the vulnerability report for coordination, any participant added to the case (including vendors) will be able to see your initial report.

What should I do if a reporter is not responding/participating?

If a reporter is not participating in the case, CERT/CC will do our best to encourage them to respond to your questions. What else?

What should I do if a vendor is not responding?

If a vendor is not participating in the case, CERT/CC will do our best to encourage them to respond but we will plan to publish a vulnerability note with or without their involvement.