You have successfully logged out.

menu
close

B. Braun Coordinated Vulnerability Disclosure

B. Braun ensures high security standards

To ensure high security standards throughout the entire product life cycle, B. Braun uses globally accepted standard testing and verification methods. We have established processes to monitor the latest vulnerabilities, threats, or risks and will proactively implement measures as required.
 

We welcome vulnerability reports from researchers, industry groups, CERTs, partners, and any other source and will give full credit on our website once the submission has been accepted and validated by our product security team. 

Use the form provided on our webpage, or equivalent protected email data to productsecurity@bbraun.com and provide us, preferably in English or German, with:
 

  • Your reference/advisory number and sufficient contact information, such as your organization and contact name so that we can get in touch with you.

 

A technical description of the concern or vulnerability

 

On which specific product you tested, including product name and version number; 

 

The technical infrastructure was tested, including operating system and version; and any relevant additional information, such as network configuration details.

 

For web-based services, the date and time of testing, URLs, the browser type and version, as well as the input provided to the application.
 

  • Any additional information, including details on the tools used to conduct the testing and any relevant test configurations. If you wrote specific proof-of-concept or exploit code, please provide a copy. 

  • If you have identified specific threats related to the vulnerability, assessed the risk, or have seen the vulnerability being exploited, please provide that information.

  • If you communicate vulnerability information to vulnerability coordinators such as ICS-CERT, CERT/CC, NCSC or other parties, their tracking number, if one has been made available.

  • A timely response to your email (within 2 business days)

  • After triage, we will send an expected timeline, and commit to being as transparent as possible about the remediation timeline as well as on issues or challenges that may extend it

  • An open dialog to discuss issues

  • Notification when the vulnerability analysis has completed each stage of our review 

  • Credit after the vulnerability has been validated and fixed.

  • Public reporting of vulnerability in appropriate circumstances

By submitting information, you agree that your submission will be governed by B. Braun’s Privacy Policy and Terms of Use.
 

We will not engage in legal action against individuals who submit reports through our vulnerability reporting process and enter into a legal agreement with us. We agree to work with individuals who:    
 

  • Engage in testing of systems/research without harming B. Braun or its customers and certainly patients.
     

  • Adhere to the laws of their location and the location of B. Braun.
     

  • Engage in vulnerability testing within the scope of our vulnerability disclosure program in accordance with the terms and conditions of any agreements entered into between B. Braun and individuals.
     

  • Refrain from disclosing vulnerability details before any mutually agreed-upon timeframe expires.
     

  • The discloser’s actions must not be disproportionate or in bad faith, such as:
     

Using social engineering to gain access to the system.
 

Building his or her own backdoor in an information system with the intention of then using it to demonstrate the vulnerability.
 

Utilizing a vulnerability further than necessary to establish its existence.

Copying, modifying or deleting data on the system or making changes to it.

Repeatedly gaining access to the system or sharing access with others.

 

Image is temporarily not available.

Vulnerability Coordination Assistance

Questions or concerns about security?

If you believe you have identified a potential security vulnerability in one of our products or services, please follow the coordinated disclosure process and fill out the form.
Click here

Stay connected with My B. Braun

With your personalized account, your online experience will be easier, more comfortable and safe.

person_outline My B. Braun