sd

Product Safety & Cyber Resilience

Cyber Resilience Act – CRA

Product Security & Cyber Resilience Act (CRA) at BOGE

The security of our products and the integrity of your systems are a high priority for the BOGE Group. Digital controls, networked compressors, and cloud-based monitoring solutions form the backbone of modern industrial processes. To ensure continuous protection, we rely on active security management and close collaboration with the global IT security community.

This page serves as the central point of contact for reporting security vulnerabilities to our Product Security Incident Response Team (PSIRT). At the same time, it outlines our Coordinated Vulnerability Disclosure policy in accordance with Annex I Part II No. 1 and No. 3 of EU Regulation 2024/2847 (Cyber Resilience Act – CRA).

1. Purpose

We take every report of a potential vulnerability in our products seriously and process it according to a defined, transparent procedure. On this page, you will find:

  • how to report vulnerabilities to our PSIRT,

  • how we handle your report, and

  • our commitments to you throughout the remediation process.

2. Scope

Covered:

  • All products with digital elements of BOGE KOMPRESSOREN Otto Boge GmbH & Co. KG and its group companies

  • Products within the committed support period

There is no entitlement to corrective measures for discontinued products.

Not covered:

  • General corporate IT and the web presence of the BOGE Group (we accept reports regarding these at the same address and forward them internally)

  • Third-party systems and services, even if they interact with BOGE products

(Please report vulnerabilities in third-party products to the respective manufacturer — if the vulnerability affects a component integrated into a BOGE product, please report it to us as well.)

3. Reporting Channel and Contact

Since information about security vulnerabilities and suspected vulnerabilities is sensitive, we ask that you transmit this information to us encrypted and use our PGP key for this purpose.

A report can also be submitted anonymously or under a pseudonym; however, without a communication channel, we cannot acknowledge receipt, ask follow-up questions, or coordinate disclosure.

  • We request machine-readable contact information.

  • Supported languages: German and English

4. Content of the Report

  • Affected Product:

    • Product designation

    • Type / Model number

    • Hardware revision

    • Firmware / Software version

    • For cloud services: the affected URL or service

  • Type of Vulnerability:

    • Brief description

    • If possible, classification (CWE) and criticality assessment (CVSS v3.1/v4.0 with vector)

  • Reproduction:

    • Steps to reproduce, test environment, and configuration

    • If applicable, Proof-of-Concept, screenshots, or log excerpts

  • Impact:

    • Which security objectives do you consider affected (Confidentiality, Integrity, Availability)?

    • Which attack scenario do you consider realistic?

  • Circumstances of Discovery:

    • When and how was the vulnerability discovered?

    • Do you have any indications of active exploitation?

  • Prior Knowledge:

    • Is the vulnerability known to third parties or already published?

    • Has the vulnerability been reported to other entities (e.g., CERTs)?

  • Contact and Disclosure:

    • Communication channel for follow-up questions

    • Name, email address, and phone number where we can reach you

    [If you wish to remain anonymous, we respect your preferences.]

    • Organizational affiliation (if applicable)

    • Your expectations regarding the timeline, form of disclosure, and attribution

5. Process

Upon receipt of your report, you will receive an acknowledgment of receipt containing a ticket number within 5 business days.

6. Rules for Responsible Disclosure

  • Confidential report

  • Reasonable timeframe

  • Coordination

  • Protection of affected organizations

As some of our components are deployed as parts of critical infrastructure, we ask that you coordinate any disclosure of information with us. This is intended to prevent publication until our development teams have prepared a suitable measure for remediation or mitigation.

7. Acknowledgments

We would like to thank everyone who submits reports for contributing to the security of our products.

8. Security Advisories

Here you will find all current security advisories issued by the PSIRT.

9. Patches and Updates

Provision can be arranged through our BOGE Support or, alternatively, via your respective BOGE partner.

10. Final Provisions

This policy may be updated at any time with future effect — the version currently published here shall apply.

As of: [04.09.2026] · Version: 1.0