Product Security Portal
Introduction
Leica Camera AG is committed to delivering products that meet high standards of quality, safety, and cybersecurity. Cybersecurity is integrated throughout the product lifecycle. Leica continuously identifies, evaluates, remediates, and communicates cybersecurity vulnerabilities affecting Leica products.
In accordance with the EU Cyber Resilience Act (Regulation (EU) 2024/2847), Leica maintains coordinated vulnerability management processes that support customers, partners, and security researchers.
Purpose
Leica Camera AG and its affiliated companies (collectively the “Leica Group”) are committed to maintaining the security of its products and services. We value the responsible efforts of security researchers, customers, partners, and other individuals who help identify cybersecurity vulnerabilities.
We currently do not operate a vulnerability reward or bug bounty program.
This Vulnerability Disclosure Policy describes how security vulnerabilities can be reported to us and how we coordinate the handling and disclosure of reported vulnerabilities in accordance with applicable cybersecurity requirements, including Regulation (EU) 2024/2847 (Cyber Resilience Act - "CRA"), where applicable, and recognized industry practices for coordinated vulnerability disclosure.
Scope
This Policy applies to the Leica Group in relation to products and services developed, manufactured, operated or supported by the respective Leica Group company. The Leica Group operates a central Product Security Incident Response Team (PSIRT) which acts as the central point of contact for vulnerability reports covered by this Policy. Reports received by the PSIRT will be assessed and, where necessary, forwarded to and coordinated with the Leica Group company responsible for the affected product or service.
It also applies to vulnerabilities affecting third-party or open-source components incorporated into or used as part of Leica Group products or services. Where a reported vulnerability originates from such a component, Leica Group will assess the impact on the affected Leica Group product or service and, where appropriate, coordinate with the relevant supplier, developer, or maintainer. Vulnerabilities exclusively affecting products or services that are neither owned, developed, operated, nor supported by Leica Group should be reported directly to the responsible provider.