Siemens Healthineers Vulnerability 
Handling and Disclosure Process

Siemens Healthineers is committed to helping to ensure the safety and security of their customers’ facilities. Siemens Healthineers follows a holistic and comprehensive approach to secure its products, solutions, services, and IT infrastructure. Siemens Healthineers has formalized a process for handling reported security vulnerabilities in its product portfolio and IT infrastructure.

Siemens Healthineers is prepared to work in good faith with individuals that submit vulnerability reports through ways described in section “Contact Information”. Siemens Healthineers openly accept reports for currently listed Siemens Healthineers products, solutions, and Siemens IT infrastructure. Siemens Healthineers maintains a Hall of Thanks to credit individuals that ethically reports security issues in Siemens Healthineers’ products, solutions, services, or infrastructure. Siemens Healthineers does not intend to engage in legal action against individuals who:

  • Engage in testing systems/research without harming anyone.
  • Test on products without affecting customers, or receive permission/consent from customers before engaging in vulnerability testing against their devices/software, etc.
  • Adhere to the applicable laws.
  • Perform coordinated disclosure, i.e. refrain from disclosing vulnerability details to the public before a mutually agreed-upon timeframe expires.
  • Avoid impact on the safety or privacy of anyone. In regard to medical products, particularly avoid impact to the safety or privacy of patients.

The vulnerability handling process consists of the following four steps at Siemens Healthineers:

To report a security vulnerability affecting a Siemens Healthineers product, solution or infrastructure component, please contact Siemens Healthineers using the ways described in section “Contact Information”. Siemens usually responds to incoming reports within one business day.

Please report the following information:

  • Description of vulnerability, including proof-of-concept exploit code or network traces (if available)
  • Affected product, solution or infrastructure component, including model and firmware version (if available)
  • Publicity of vulnerability (was it already publicly disclosed?)
  • Everyone is encouraged to report discovered vulnerabilities, regardless of service contracts or product lifecycle status. Siemens Healthineers welcomes vulnerability reports from researchers, industry groups, CERTs, partners and any other source as Siemens Healthineers does not require a nondisclosure agreement as a prerequisite for receiving reports. Siemens Healthineers respects the interests of the reporting party (also anonymous reports if requested) and agrees to handle any vulnerability that is reasonably believed to be related to Siemens Healthineers products, solutions or infrastructure components. Siemens Healthineers urges reporting parties to perform a coordinated disclosure, as immediate public disclosure causes a ‘0-day situation’ which puts Siemens Healthineers’ customer systems at unnecessary risk. Those systems comprise significant parts of the worldwide critical infrastructure.

Siemens Healthineers shall investigate and reproduce the vulnerability. If needed, Siemens Healthineers will request more information from the reporter.

Siemens Healthineers will perform internal vulnerability handling in collaboration with the responsible development groups. National and Governmental CERTs having a partnership with Siemens Healthineers PSIRT and CSIRT may be notified about a security issue in advance. During this time, regular communication is maintained between Siemens Healthineers and the reporting party to inform about the current status and to ensure that the vendor’s position is understood by the reporting party. If available, pre-releases of software fixes may be provided to the reporting party for verification.

After the issue was successfully analyzed and if a fix is necessary to cope with the vulnerability, corresponding fixes will be developed and prepared for distribution. Siemens Healthineers will use existing customer notification processes to manage the release of patches, which may include direct customer notification, or public release of a security advisory.

A Siemens Healthineers Security Advisory usually contains the following information:

  • Description of the vulnerability with CVE reference and CVSS score
  • Identity of known affected products and software/hardware versions
  • Information on mitigating factors and workarounds
  • The location of available fixes
  • With the reporting party’s consent, credit is provided for reporting and collaboration.

The Terms of Use of the Siemens Healthineers Security Advisories are designed to encourage distribution of reliable security information for any stakeholder, commercial, public or private.

V1.0 (20226-09-16): Initial Draft for Publication

Get In Touch


Siemens Healthineers PSIRT (Product Security Incident Response Team) or Siemens Healthineers CSIRT (CyberSecurity Incident Response Team)
For Siemens Healthineers portfolio/infrastructure security questions or to report potential issues, please contact us. We accept English or German emails; encrypted communication is preferred.

Siemens Healthineers PSIRT - contact for Products / Portfolio
PGP Public Key and Fingerprint: Needs to be generated
Email: productsecurity@siemens-healthineers.com

Siemens Healthineers CSIRT - contact for infrastructure
PGP Public Key and Fingerprint: CSIRT will update it
Email: csirt@siemens-healthineers.com