Report a vulnerability

General information​
Affected Product​
e.g. 101234567 123
e.g. BVC 180, BVC 250 Candy, BVC 145 TwinTube, CMH-I 9, CMV, SBS 250, VDX-6
Description of the Vulnerability or Cybersecurity Incident​
What exactly happened?
If you answered ‘Yes’ to the question ‘Has the vulnerability been actively exploited?’
If you answered ‘No’ or ‘Unclear’ to the question ‘Has the vulnerability been actively exploited?’
e.g. system isolated, access blocked, security update installed

**An actively exploited vulnerability is a vulnerability for which reliable evidence exists that a malicious actor has exploited it in the affected product without the consent of the system owner. For example, a malicious actor would have to have demonstrably changed a function of the product by exploiting a vulnerability present in our product without you having given consent. We are obligated to report actively exploited vulnerabilities to the competent authorities (for further information on the handling of vulnerabilities, see CVD).

Note: Please do not provide personal data relating to third parties. Free-text fields, attachments, and uploads should only contain such data where it is necessary to describe and process the reported vulnerability or cybersecurity incident.​ The personal data provided will be processed for the purpose of reviewing and handling the report.​

Reporting by Email​

Submitting reports via our reporting form and providing the requested information helps ensure the efficient handling of vulnerability and cybersecurity incident reports.​

By sending this email, you confirm that you have read and understood the privacy notice set out above and the linked privacy policies. These notices also apply accordingly to the content of your email and any attachments you have sent.

vulnerability(at)rovema.de