Security Vulnerability Disclosure & Bug Bounty Policy
Silicon Labs is a leader in secure, intelligent wireless technology for the connected world. Our mission is to empower developers to create wirelessly connected devices that transform industries, grow economies, and improve lives. The security of our corporate infrastructure and product technologies is critical to our business, to growing customer relationships, to maintaining the trust of our users, and to doing the right thing. Silicon Labs recognizes the important role that security researchers play in keeping our systems and products secure and values our relationship with the security community. Silicon Laboratories Inc. (“Silicon Labs”, “we”, or “our”) looks forward to working with the security community to find vulnerabilities to keep our businesses and customers safe.
Silicon Labs recognizes the important role that security researchers play in keeping our organization, our customers, and our users safe. 私たちは、技術の弱点を特定して修正するには、熟練したセキュリティ研究者たちと協力し合うことが重要であると考えています。If you’ve identified a potential security vulnerability in our product, services, or infrastructure, please report it to us as soon as possible. We look forward to working with you and doing our best to address the issue quickly.
If you have found a vulnerability, please register or log in as a researcher on the Silabs Community Page, and a form will be provided for your vulnerability report.
The list below defines the scope of the Silicon Labs VDP and Bug Bounty program:
- Newly discovered security vulnerabilities that occur with Silicon Labs products, reference designs, web assets, or enterprise infrastructure and are not already covered in published documents/forums.
- Silicon Labs infrastructure, products, or systems that are being used or accessed unexpectedly.
- Does not include sample/example applications in the SDK or GitHub repositories.
略語/定義
- PCN – Product Change Notification(製品変更通知)
- PSIRT – Product Security Incident Response Team(製品セキュリティ・インシデント対応チーム)
- ESIRT – Enterprise Security Incident Response Team(エンタープライズ・セキュリティ・インシデント対応チーム)
- RFI – Request for Information(情報の要請)
脆弱性の報告
The security of our products and infrastructure is critical to our business. This program is a key part of our security strategy. We recognize your time and effort and are committed to doing the right thing for our researchers, customers, and users. Payouts are based on CVSS scores as determined by the Silicon Labs PSIRT team and will follow our response targets and rewards structure as shown below. Vulnerabilities or suspicious functionality in products may be reported by customers (via their supporting Field Applications Engineers), Silicon Labs employees (via internal reporting method), and researchers or other interested parties (via our Silicon Labs Community Page). When a security vulnerability is suspected, please register or log in as a researcher on our Silicon Labs Community Page, and a form will be provided for your vulnerability report.
セキュリティ応答プロセス
When a security vulnerability is suspected, complete and submit a report. The report will be sent to the Silicon Labs PSIRT/ESIRT team. An acknowledgment by Silicon Labs will occur within three business days of receipt of the report, and triage by Silicon Labs will follow the response targets below.
Our ESIRT and PSIRT work with other Silicon Labs groups including Applications Engineers, Engineers, Developers, Product Managers, Sales, and Marketing to assess reported vulnerabilities, perform technical analysis, and determine an appropriate response. 脆弱性に対処するための主要なプロセスは次のとおりです。
- トリアージ:This involves active dialog between the ESIRT/PSIRT, the reporting entity, the Applications Support Team, as well as the Engineering Design team, to determine what is needed to reproduce the vulnerability.
- 次の手順:This involves the actual confirmation of the validity of the security vulnerability based on the issue’s evaluation and/or reproduction. The scope and impact or severity of the vulnerability are confirmed, as well as a resolution or disposition decision. This may include a fix, workaround, or acceptance of the identified vulnerability.
- アウトプット:This conditionally includes an official fix, recommended mitigating actions, assignment of CVE ID(s), and an official Silicon Labs security advisory. 報告機関を超えた開示のレベルは、脆弱性の重大度と範囲によって異なります。
回答対象
Silicon Labs は、本プログラムの参加者のために、以下の SLA を満たすべく合理的な努力を行っていきます。
| 回答の種類 | 営業日の ESIRT SLA | 営業日の PSIRT SLA |
|---|---|---|
| 最初の対応 | 3 日 | 3 日 |
| トリアージまでの時間 | 15 日 | 15 日 |
| 解決までの時間 | 重大度と複雑さによって異なる | 重大度と複雑さによって異なる |
Our Approach to Bug Bounty
We are excited to work with you to make our products more secure and strengthen our engagement with the security community. We strive to:
- Be as transparent as possible.
- Reply to reports as quickly as possible to reduce the likelihood of duplicate work for our researchers.
- Compensate researchers as quickly as possible once we validate the report.
- Work with security researchers as peers and assume the best in interactions with the security community.
Bounties
Bounties are paid out based on the PSIRT priority according to the confirmed PSIRT priority rating, which is determined by a Silicon Labs review process. Once you register as a researcher at community.silabs.com, payments for the confirmed reported vulnerabilities will be based on priority as described in the Vulnerability Disclosure Program (VDP) FAQ.
Silicon Labs may, at its sole discretion, offer certain monetary rewards for vulnerability disclosure. Bounty amounts are determined by Silicon Labs and subject to the following eligibility requirements:
- Due to U.S. trade restrictions and/or export sanctions, we cannot issue payments to individuals residing in or reporting from countries subject to U.S. sanctions (as defined by the U.S. Office of Foreign Assets Control, including but not limited to Burma, China, Cuba, Iran, North Korea, Russia, Belarus, Sudan, Syria, and Venezuela).
- Minors may participate, but anyone under 18 must have a parent or legal guardian claim the bounty on their behalf to comply with COPPA and other applicable laws.
- All payments are made in U.S. dollars and must comply with local laws, regulations, and ethics rules. You are responsible for any applicable taxes related to any payments that you receive.
- You are responsible for complying with your employer’s policies regarding participation in this program
開示方針
- 参加の条件として、お客様は、Silicon Labs からの明示的な同意なしに、このプログラムについて議論したり、プログラムの外の脆弱性(解決済みのものも含む)を開示しないことに同意するものとします。
プログラムのガイドライン
To protect our company, customers, and users, you must accept and comply with the following guidelines:
- Silicon Labs の事前の書面による許可なしに、潜在的なセキュリティ問題を第三者に開示しないこと。
- Reports must provide enough detail to reproduce the issue. If a report is not detailed enough to reproduce the reported issue, the issue may not be accepted as a vulnerability.
- 影響をもたらすために複数の脆弱性を連鎖させる必要がある場合を除き、レポートあたり 1 件の脆弱性のみとなります。
- 重複して受け取った場合、最初に受領した報告書のみがトリアージされます(ただし、完全に再生できることが条件)。
- 1つの根本的な問題に起因する複数の脆弱性は、1つの有効なレポートとして扱われます。
- Ensure your research complies with all relevant laws and regulations. Conduct research only on Silicon Labs products and websites, in accordance with their terms and conditions (e.g., Community Terms of Use, Master Service License Agreement, Terms and Conditions of Sale), and all publicly posted policies, guidelines, and instructions.
- プライバシーの侵害、データの破壊、当社サービスの中断や劣化を回避する。所有しているアカウントに対してのみやり取りは(またはアカウント所有者の明示的な許可に基づいて)。
- 当社の顧客または潜在的な顧客に対するいかなるスパム行為にも関与しないこと。
- Do not engage in social engineering (e.g., phishing, vishing, smishing).
- Silicon Labs の資産またはデータセンターに対する物理的な試みに関わらないこと。
- 危害を加えないでください。脆弱性は速やかに報告し、公共の利益のために行動してください。If you confirm a vulnerability (e.g., proof-of-concept achieved) or encounter sensitive data — including personal, financial, proprietary, or trade-secret information — stop immediately and report it. そのデータへのアクセス、コピー、変更、保存、転送、またはさらなる調査は行わないでください。報告後は、保有している当該情報を速やかに削除してください。
- サービス拒否を行わないこと。
- 報告が提出されると、Silicon Labsはすべての報告について速やかに受領確認(提出から3営業日以内)を行い、本プログラムを通じて報告された有効な脆弱性の対応状況について、合理的な範囲で継続的にお知らせします。
- お客様は、レポートの内容をいかなる目的にも使用できる権利を当社に付与します。
- レポートを提出しても、お客様と Silicon Labs との間に消費者、雇用、あるいは代理店関係は生じません。
- Silicon Labs may update this policy at any time.
Web 資産の範囲外となっている脆弱性
脆弱性を報告する際には、(1)攻撃のシナリオ/エクスプロイトの可能性、および(2)そのバグのセキュリティに対する影響について考慮してください。以下の問題は範囲外と見なされます。
- 機密性が高いアクションを含まないページのクリックジャッキング。
- 認証されていないフォーム、または機密性の高いアクションを含まないフォームのサイト間リクエストの偽造(CSRF)。
- ユーザーのデバイスへの MITM や物理的アクセスを要する攻撃。
- 機能する概念実証のない、既知の脆弱なライブラリ。
- 脆弱性を示していない、カンマ区切り値(CSV)のインジェクション。
- SSL/TLS 構成にベストプラクティスがありません。
- 当社サービス(DoS)の中断につながる可能性のあるアクティビティ。
- 攻撃ベクトルを表示しない HTML/CSS を変更できないコンテンツ・スプーフィングとテキスト・インジェクションに関する問題。
- Rate limiting or brute-force issues on non-authentication endpoints.
- コンテンツ セキュリティ ポリシーのベスト プラクティスがありません。
- Cookie に HttpOnly または Secure フラグがありません。
- メールのベストプラクティスがない(無効、不完全、または SPF/DKIM/DMARC 記録がないなど)。
- 古いブラウザやパッチが適用されていないブラウザのユーザーのみに影響を与える脆弱性 [最新の安定したバージョン 2 件よりも安定したバージョンが少ない]。
- ソフトウェア・バージョンの開示/バナーの識別問題/説明的なエラーメッセージまたはヘッダー(スタックトレース、アプリケーションまたはサーバーのエラーなど)。
- タブナビング
- オープン・リダイレクト - 追加のセキュリティ影響が実証できる場合を除く。
- 好ましくないユーザーのやり取りが必要な問題。
Out of Scope Vulnerabilities for Products
- Eligible vulnerabilities should not rely on physical tampering of the device, but be restricted to what on-chip or off-chip software is exploitable; however, Side Channel Analysis and Fault Injection testing are in-scope for the program.
- 一般:アライメント、外観、ドキュメントのエラー/スペル、以前のリリースと最新のツールチェーン間の非互換性。
- Vulnerabilities in development branches (such as alpha and beta versions of code or features supported for development only).
- Any 3rd party software.
- Sample/Example code/programs.
- Vulnerabilities in deprecated releases.
- Any attack preventable by existing security features.
- Silicon Labs employees are expected to make submissions internally and are not eligible for the bug bounty program.
複数の資産にわたる反復バグに関する方針
Silicon Labs often has the same code deployed in multiple branches, meaning that a single vulnerability is independently fixable in multiple locations. It is our policy to count this as one vulnerability for the sake of the Vulnerability Disclosure Policy/Bug Bounty. As such, we will only pay bounties on the first report of a vulnerability to a specific piece of code — vulnerabilities on multiple parameters in the same form will be treated as the same vulnerability.
High Priority Assets/Features
Silicon Labs は、以下のコンポーネントに関連するセキュリティ問題に非常に関心があります。
- AES128/192/256、ChaCha20-Poly1305、SHA-1、SHA-2/256/384/512、ECDSA+ECDH (P-192、P-256、P-384、P-521)、Ed25519、および Curve25519、J-PAKE、PBKDF2 向けハードウエア暗号化アクセラレーション
- 真の乱数発生器(TRNG)
- ARM® TrustZone®
- セキュアブート(信頼できるセキュア・ローダーのルート)
- セキュア・デバッグ・アンロック
- DPA 対策
- PUF による安全な鍵管理
- Anti-Tamper Secure Attestation
- Wireless Stack
- Platform Security Features
- Gecko ブートローダー
- Gecko SDK
- 917 bootloader
その他
This program is not open to minors, individuals who are on sanctions lists, or who are in countries (e.g., Cuba, Iran, North Korea, Sudan, and Syria) on sanctions lists. You are responsible for any tax implications resulting from payouts depending on your country of residency and citizenship. Silicon Labs reserves the right to cancel this program at any time, and the decision to pay a bounty is entirely at our discretion. Your testing and submission must not violate any law or disrupt or compromise any data that is not your own. There may be additional restrictions on your ability to submit content or receive a bounty depending on your local laws.
安全ルール
Any activities conducted in accordance with the restrictions and guidelines outlined in this policy will be considered authorized conduct under the Computer Fraud and Abuse Act. If legal action is initiated by a third party against you and you have fully complied with this program, Silicon Labs will take steps to make it known, either to the public or to the court, that your actions were conducted in compliance with the Silicon Labs policy.
Silicon Labs とユーザーの安全を守るためにご協力いただきありがとうございます。
研究者が使用するリソース
| 参照タイトル | リンク | 目的 |
|---|---|---|
| コミュニティリンク | https://community.silabs.com/s/ | 技術サポート用参考文献 |
| ユーザー向けプロジェクトページ | https://community.silabs.com/s/all-blogs?language=en_US | 様々なプロジェクトやタイムラインに関するブログ |
| キットの注文 | https://www.silabs.com/development-tools | 検査用キットの注文方法 |
製品の開示声明
Silicon Labs は、当社製品に関連するセキュリティ関連の懸念に関する最新かつ最も正確な文書をお客様に提供したいと考えています。There are multiple methods for disclosing security-related updates, including:
- PCN – Product Change Notification(製品変更通知)
- リリースノート – ソフトウェアのリリース時に提供される文書
- お客様との直接のコミュニケーション – セールスまたはフィールド・アプリケーション・エンジニアを介したコミュニケーション
- セキュリティ・アドバイザリー - セキュリティ問題とその対処法に関する技術的要約
Use of products by customers must follow the provided specifications for operation to ensure proper functionality. セキュリティ上の懸念が報告された場合、Silicon Labs は詳細を分析し、Silicon Labs の製品またはソフトウェアへの影響を評価し、関連する技術的原因を判断し、適切な解決策および/または開示を提供します。
Silicon Labs は、セキュリティまたは信頼性の理由から必要な場合、(ソフトウェア/ハードウェア)製品を調整する権利を留保します。脆弱性に関する情報の共有は、リリースノート、PCN、アドバイザリ、アプリケーションノート、FAQ などの形式をとる場合があります。
Read details on the Terms & Conditions and product-specific disclaimer content. Requests for product-related content not readily on our website may be made through our authorized sales channel.
