en-GB
dd/MM/yyyy

Optoma

Loading ring icon

Coordinated Vulnerability Disclosure (CVD) Policy

Purpose

Optoma is committed to maintaining the security of its products with digital elements, including related software, firmware and remote data processing solutions, and recognises the valuable role that customers, partners, security researchers and the wider security community play in identifying potential security vulnerabilities.

This Coordinated Vulnerability Disclosure Policy explains how potential security vulnerabilities may be reported to us and how we manage and respond to such reports.

Scope

This Policy applies to potential security vulnerabilities affecting Optoma products with digital elements, including related software, firmware and remote data processing solutions that are developed, provided or maintained by Optoma. In-scope products include:

  • Optoma projectors;
  • Optoma interactive flat panel displays;
  • Optoma software applications;
  • Optoma firmware;
  • Optoma cloud-based product management platforms and related remote data processing solutions;
  • Other Optoma products with digital elements that are developed, provided or maintained by Optoma; or
  • Third-party components that are integrated into, or distributed as part of, an Optoma product with digital elements.

The following are generally outside the scope of this Policy:

  • Product support requests;
  • General customer service enquiries;
  • Feature requests or product enhancement suggestions;
  • Social engineering attacks against Optoma personnel;
  • Physical security issues that do not involve cybersecurity vulnerabilities;
  • Third-party products, software or remote data processing solutions not developed, provided or maintained by Optoma.

Report a Security Vulnerability

We welcome reports of potential security vulnerabilities from customers, partners, security researchers and other members of the security community. If you believe you have identified a security vulnerability affecting any of our products with digital elements, including related software, firmware or remote data processing solutions, we encourage you to report it to our Product Security Incident Response Team (PSIRT).

Reports may be submitted through our online submission form at Vulnerability Report.

To assist us in investigating the reported issue, please include where possible:

  • Product name and model number;
  • Software, firmware or application version;
  • Description of the vulnerability;
  • Steps required to reproduce the issue;
  • Technical details sufficient to understand and reproduce the issue;
  • Proof-of-concept information (if available);
  • Information regarding any observed exploitation;
  • Your contact information.

Any personal data provided in connection with a vulnerability report will be processed in accordance with our Privacy Policy. Please refer to our Privacy Policy for further information about how Optoma processes personal data.

Optoma's Commitments

Upon receiving a vulnerability report, Optoma will:

  • Acknowledge receipt of the report where appropriate;
  • Review the report and determine whether sufficient information has been provided;
  • Investigate the reported issue in a timely and appropriate manner;
  • Assess the potential security impact of the reported vulnerability;
  • Work towards developing appropriate remediation, mitigation or corrective measures where necessary;
  • Communicate with the reporter regarding the status of the report where appropriate;
  • Coordinate disclosure in a manner intended to protect customers and support the effective remediation of security vulnerabilities.

Submission of a report does not guarantee that the reported issue constitutes a security vulnerability or that remediation will be required.

Responsible Security Research

Optoma welcomes good-faith security research intended to improve the security of its products with digital elements, including related software, firmware and remote data processing solutions.

When conducting security research, we ask that researchers:

  • Act in good faith and in a responsible manner;
  • Do not access, modify, delete or retain customer data except to the minimum extent necessary to verify the existence of a suspected vulnerability;
  • Avoid activities that could compromise the privacy, confidentiality, integrity or availability of Optoma systems, customer systems, customer accounts or customer data;
  • Avoid service disruption, denial-of-service activities or other activities that may adversely affect users or customers;
  • Limit testing to the minimum extent necessary to identify and verify a suspected vulnerability;
  • Immediately cease testing if access to customer data or personal data is obtained unintentionally;
  • Not retain, copy, disclose or otherwise use any data accessed unintentionally during research activities;
  • Comply with all applicable laws and regulations;
  • Promptly report identified vulnerabilities to Optoma through the reporting channels identified in this Policy.

Coordinated Disclosure

Optoma requests that individuals reporting vulnerabilities:

  • Do not publicly disclose vulnerability details before Optoma has had a reasonable opportunity to investigate and, where appropriate, remediate the issue;
  • Do not disclose information that may increase the risk of exploitation before appropriate mitigation measures are available;
  • Cooperate with Optoma during the vulnerability assessment and remediation process.

Optoma may coordinate public disclosure of vulnerability information with the availability of security updates, mitigations, advisories or other corrective measures.

Safe Harbour

We welcome and encourage good-faith security research that is conducted in accordance with this Policy.

Where we determine that a researcher has acted in good faith, complied with this Policy and made reasonable efforts to avoid harm to us, our customers, suppliers, users and systems, we will not initiate legal action against the researcher solely in connection with activities conducted under this Policy.

This Safe Harbour provision does not apply to activities that:

  • Intentionally access, modify or destroy data;
  • Violate applicable law;
  • Disrupt our systems, products or services;
  • Involve unauthorised access to customer accounts, customer systems or personal data;
  • Cause harm to us, our customers, suppliers, users or third parties.

Nothing in this Policy authorises any activity that is prohibited by applicable law.

Vulnerability Information and Security Advisories

Where appropriate, we may publish security advisories, release notes, security updates or other notifications relating to confirmed vulnerabilities.

We may acknowledge the contribution of security researchers who report vulnerabilities, subject to the preferences of the researcher and applicable legal or contractual obligations.

Amendments

We may update this Policy from time to time to reflect changes in legal requirements, industry practices, products, services or security processes.

The most current version of this Policy will be published on our website.