Thank you for helping improve the security of Leica products.
If you believe you have discovered a security vulnerability in one of our products or services, please report it as soon as possible by email.
Email: psirt@leica-camera.com
We kindly ask you not to publicly disclose a reported vulnerability until Leica Group has had a reasonable opportunity to investigate and remediate or mitigate the issue.
Leica Group will seek to coordinate the timing of any public disclosure with the reporter, taking into account the severity of the vulnerability, the availability and deployment of a remediation, the potential impact on users, and any applicable legal or regulatory obligations.
Information to Include
To help us investigate your report efficiently, please include as much of the following information as possible:
- Vulnerability title
- Product name and model
- Affected URL or service (where applicable) (optional)
- Software or firmware version
- Description of the vulnerability
- Potential security impact
- Weakness classification (e.g., CWE), if known (optional)
- Severity assessment (e.g., CVSS), if known (optional)
- Steps to reproduce the issue
- Supporting evidence (such as screenshots, logs, or proof of concept)
- Possible mitigation or recommendation (optional)
- Your contact information for follow-up questions (optional)
- Please avoid including personal data, confidential information, or data relating to third parties in your report unless this is strictly necessary to demonstrate the vulnerability. Where possible, redact or anonymize such information before submitting it.
Our Commitment
Upon receiving a vulnerability report, we will:
- Acknowledge receipt of your report within 5 business days.
- Review and assess the reported vulnerability.
- Aim to complete the initial technical assessment within 10 business days, were reasonably practicable.
- Contact you if additional information is required.
- Keep you informed of significant progress where appropriate.
- Notify you when our investigation has been completed and, where appropriate, when a remediation or mitigation is available.
Where a reported vulnerability affects third-party components or suppliers, additional coordination may be required, and resolution timelines may be extended.
Vulnerabilities are prioritized based on their potential impact, severity, exploitability, and the affected products or services. Investigation and remediation timelines may vary depending on the complexity of the issue.