Siemens Healthineers is committed to helping to ensure the safety and security of their customers’ facilities. Siemens Healthineers follows a holistic and comprehensive approach to secure its products, solutions, services, and IT infrastructure. Siemens Healthineers has formalized a process for handling reported security vulnerabilities in its product portfolio and IT infrastructure.
Siemens Healthineers is prepared to work in good faith with individuals that submit vulnerability reports through ways described in section “Contact Information”. Siemens Healthineers openly accept reports for currently listed Siemens Healthineers products, solutions, and Siemens IT infrastructure. Siemens Healthineers maintains a Hall of Thanks to credit individuals that ethically reports security issues in Siemens Healthineers’ products, solutions, services, or infrastructure. Siemens Healthineers does not intend to engage in legal action against individuals who:
- Engage in testing systems/research without harming anyone.
- Test on products without affecting customers, or receive permission/consent from customers before engaging in vulnerability testing against their devices/software, etc.
- Adhere to the applicable laws.
- Perform coordinated disclosure, i.e. refrain from disclosing vulnerability details to the public before a mutually agreed-upon timeframe expires.
- Avoid impact on the safety or privacy of anyone. In regard to medical products, particularly avoid impact to the safety or privacy of patients.
The vulnerability handling process consists of the following four steps at Siemens Healthineers:
1. Report
To report a security vulnerability affecting a Siemens Healthineers product, solution or infrastructure component, please contact Siemens Healthineers using the ways described in section “Contact Information”. Siemens usually responds to incoming reports within one business day.
Please report the following information:
- Description of vulnerability, including proof-of-concept exploit code or network traces (if available)
- Affected product, solution or infrastructure component, including model and firmware version (if available)
- Publicity of vulnerability (was it already publicly disclosed?)
- Everyone is encouraged to report discovered vulnerabilities, regardless of service contracts or product lifecycle status. Siemens Healthineers welcomes vulnerability reports from researchers, industry groups, CERTs, partners and any other source as Siemens Healthineers does not require a nondisclosure agreement as a prerequisite for receiving reports. Siemens Healthineers respects the interests of the reporting party (also anonymous reports if requested) and agrees to handle any vulnerability that is reasonably believed to be related to Siemens Healthineers products, solutions or infrastructure components. Siemens Healthineers urges reporting parties to perform a coordinated disclosure, as immediate public disclosure causes a ‘0-day situation’ which puts Siemens Healthineers’ customer systems at unnecessary risk. Those systems comprise significant parts of the worldwide critical infrastructure.
2. Analysis
Siemens Healthineers shall investigate and reproduce the vulnerability. If needed, Siemens Healthineers will request more information from the reporter.
3. Handling
Siemens Healthineers will perform internal vulnerability handling in collaboration with the responsible development groups. National and Governmental CERTs having a partnership with Siemens Healthineers PSIRT and CSIRT may be notified about a security issue in advance. During this time, regular communication is maintained between Siemens Healthineers and the reporting party to inform about the current status and to ensure that the vendor’s position is understood by the reporting party. If available, pre-releases of software fixes may be provided to the reporting party for verification.
4. Disclosure
After the issue was successfully analyzed and if a fix is necessary to cope with the vulnerability, corresponding fixes will be developed and prepared for distribution. Siemens Healthineers will use existing customer notification processes to manage the release of patches, which may include direct customer notification, or public release of a security advisory.
A Siemens Healthineers Security Advisory usually contains the following information:
- Description of the vulnerability with CVE reference and CVSS score
- Identity of known affected products and software/hardware versions
- Information on mitigating factors and workarounds
- The location of available fixes
- With the reporting party’s consent, credit is provided for reporting and collaboration.
The Terms of Use of the Siemens Healthineers Security Advisories are designed to encourage distribution of reliable security information for any stakeholder, commercial, public or private.
History
V1.0 (20226-09-16): Initial Draft for Publication