Back

MiTAC Computing Vulnerability Response Policy

Introduction

MiTAC Computing is committed to helping customers minimize the risks associated with security vulnerabilities in its products. Our objective is to provide customers with timely information, guidance, and risk mitigation options for addressing vulnerabilities. The MiTAC Computing Product Security Incident Response Team (MiTAC Computing PSIRT) is responsible for coordinating the response to, and disclosure of, product vulnerabilities that may affect MiTAC Computing products. MiTAC Computing recommends that all customers migrate to supported versions of MiTAC Computing products before the end of the applicable support period in order to continue receiving security updates.

Handling Vulnerability Reports

Customer security is MiTAC Computing's highest priority. We therefore place significant value on the contributions made by our industry partners and security researchers to our security practices, and we encourage responsible, coordinated disclosure. Our goal is to ensure that, when vulnerabilities specific to MiTAC Computing are disclosed, appropriate remediation and/or mitigation strategies are available, and that we collaborate with third-party vendors when remediation requires their participation.

Under this policy, all disclosure information related to new vulnerabilities is considered confidential. Until such information is publicly announced, it should be shared only between MiTAC Computing and the reporting party, pending the availability of remediation and the coordination of disclosure activities.

How to Report a Security Vulnerability

If you identify a security vulnerability in any MiTAC Computing product, please submit a product vulnerability report as soon as possible through one of the reporting channels below. Enterprise and commercial product customers and partners should contact their respective technical support teams to report any security issue identified in MiTAC Computing products. The technical support team, the appropriate product team, and the Product Security Incident Response Team (PSIRT) will work together to address the reported issue and provide customers with next steps.

Vulnerability Reporting Channels

  • Submit a vulnerability report form through the public vulnerability reporting page on the official website.
  • Submit the issue by email.

If you are unable or unwilling to use the vulnerability report form, you may also send the issue to [email protected] (Product Security Incident Response Team). Please encrypt all email communications using the PGP public key. Provide as much detail as possible about the vulnerability, including its name, time of discovery, issue summary, product or system URL, product version, distribution/source location, reproduction steps, and/or proof of concept.

Vulnerability Remediation

After investigating and validating a reported vulnerability, MiTAC Computing will use commercially reasonable efforts to develop and approve appropriate remediation for MiTAC Computing products that remain under active support. Remediation may take one or more of the following forms:

  • A new version of the affected product packaged by MiTAC Computing, such as BIOS or firmware.
  • Download and installation instructions for updates or patches provided by third-party vendors to remediate the vulnerability.
  • When a vendor has not yet released a patch for a specific vulnerability, the organization should adopt mitigation measures to reduce the potential impact of exploitation.
  • Acceptance of the identified risk.
    • For low-risk vulnerabilities that pose minimal threat to the business, no action may be taken on the identified vulnerability.
    • When the cost of remediation exceeds the potential cost of exploitation, no action may be taken on the identified vulnerability.

Security Advisories

MiTAC Computing publishes the latest security information for MiTAC Computing server products to communicate information about security vulnerabilities affecting our products to customers.

To read the full version of this policy, please refer to this file: Vulnerability Disclosure Policy.

SUBSCRIBE NOW to get the latest news.

Clicking "OK" confirms your acceptance of our Terms of Use, Privacy Policy, and Cookie Policy.