Top

Cyber ​​Resilience Act (CRA): vulnerability reporting channel now active

LAE Electronic provides a dedicated point of contact for reporting vulnerabilities and security issues affecting its products: [email protected]

Why

LAE Electronic products are electronic devices with embedded software, designed primarily for control and thermoregulation in refrigeration applications. As such, they fall within the scope of Regulation (EU) 2024/2847 — the Cyber Resilience Act (CRA), which introduces cybersecurity requirements for products with digital elements placed on the European market.

Among these requirements, manufacturers must adopt a coordinated vulnerability disclosure policy and make publicly available a contact address through which anyone can report vulnerabilities found in their products.

In order to meet these obligations — and, more broadly, as part of our ongoing commitment to improving the security of our solutions — LAE Electronic has set up a dedicated and actively monitored mailbox.

Who it is for

The channel is open to everyone: OEM customers, installers, end users, security researchers, technology partners and suppliers.

What to report

  • Potential or confirmed vulnerabilities in LAE Electronic products (hardware, firmware, configuration software and related tools)
  • Actively exploited vulnerabilities
  • Security incidents involving a LAE Electronic product
  • Unexpected behaviour that may affect the security of the product or of the system it is installed in

How to report

To help us assess your report as quickly and effectively as possible, please include the following information, to the extent known to you:

  • Product concerned: part number, model and, where available, serial or batch number
  • Firmware/software version
  • Description of the issue and its potential security impact
  • Steps to reproduce, test setup and relevant environmental conditions
  • Any supporting material: logs, screenshots, communication traces, references to CVEs or published research
  • Your contact details, so that we can ask for clarification and keep you informed of the outcome

Please do not include personal data or confidential information that is not strictly necessary for the analysis.

How we handle reports

  1. Acknowledgement — we confirm receipt of your report, normally within 5 working days.
  2. Analysis — we assess reproducibility, impact, and the products and versions affected.
  3. Remediation — we define and develop the necessary countermeasures, prioritised by severity.
  4. Communication — we inform affected customers and, where applicable, notify the competent authorities within the timeframes set out by the Cyber Resilience Act.
  5. Feedback — we keep the reporter informed of progress and of the final outcome.

All reports are treated confidentially. Unless you tell us otherwise, we will not disclose your identity. If you wish to be credited in any public reference to the vulnerability, please let us know.

We follow a coordinated disclosure approach: we ask reporters not to make information public before the necessary countermeasures are available, so that users are not exposed to avoidable risk.

What this channel is not for

The [email protected] mailbox is exclusively dedicated to security reports.

For technical assistance, sales enquiries, orders or application support, please use the usual channels listed in the Contacts section of this website.

Legal reference: Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 (Cyber Resilience Act).