sign in
logout
CN
Email Us

UNICORE PSIRT

UNICORE PSIRT

UNICORE PSIRT

UNICORE PSIRT stands for UNICORE Product Security Incident Response Team (UNICORE Product Security Incident Response Team). UNICORE PSIRT is a dedicated team responsible for receiving, verifying, and disclosing vulnerabilities related to UNICORE products. UNICORE defines vulnerabilities as security issues exploitable within products that, once exploited by attackers, can compromise the integrity, usability, or confidentiality of the product. A vulnerability is not the same as a quality defect. A quality defect is triggered when the trigger conditions are met without the need for an attacker to exploit it, whereas a vulnerability must be exploited by an attacker before it is triggered. UNICORE encourages security researchers, industry organizations, customers, and suppliers to report suspected vulnerabilities related to UNICORE products to the UNICORE PSIRT, which will handle suspected vulnerabilities in UNICORE products in accordance with industry standards such as ISO/IEC30111 and ISO/IEC 29147.


Vulnerability reporting

Report suspected vulnerabilities

If you encounter or discover suspected vulnerabilities in UNICORE products, you are welcome to promptly notify UNICORE PSIRT and refer to vulnerability reporting channels and security mechanisms to submit suspected vulnerabilities.


Vulnerability reporting channels

You can submit suspected vulnerabilities related to UNICORE products via email according to the template. UNICORE PSIRT will promptly verify any suspected vulnerabilities reported by security researchers, industry organizations, customers, and suppliers. To encourage vulnerability reporting, UNICORE has established the UNICORE Security Rewards Program.

ChannelsExplanation
Email: psirt@unicorecomm.comUsually, you will receive an email confirmation from UNICORE PSIRT within 24 hours, and the progress of the issue will be updated accordingly.

Security mechanisms

Given the sensitivity of the vulnerability information, to ensure confidentiality, we recommend using PGP (Pretty Good Privacy) to encrypt information sent to psirt@huawei.com. Our PGP public key (key ID 0x058FBDFC; PGP fingerprint: D0D8 6234 08CF ED7E 39B8 1C71 21A2 3355 058F BDFC) can be obtained by clicking here.


Throughout the entire vulnerability handling process, Huawei PSIRT strictly controls the scope of vulnerability information, only passing it on among the relevant personnel handling the vulnerability; We also request that the whistleblower keep this vulnerability information confidential until our client obtains a complete solution.


Response range

UNICORE  PSIRT focuses on receiving all vulnerabilities related to Huawei products; For UNICORE product issues (such as product configuration, patch acquisition, and current network vulnerability repair support), you can directly contact UNICORE TAC (UNICORE Technical Assistance Center) for relevant technical support. UNICORE will handle vulnerabilities identified by TAC during technical support according to internal procedures.




CONTACT
Subscribe
Subscribe to get news updates from us
We use cookies to allow our website to function properly, personalize content,advertising, and analyze traffic. Respect for your privacy is central to our policy. Detailed information about our privacy and cookie policy can be found in the enclosed sections. Thanks in advance for your cooperation. More info...
Reject Accept