BAUER Product Security

Report a Cybersecurity Vulnerability or Security Incident

BAUER welcomes reports from customers, users, suppliers, service providers, security researchers, white-hat hackers, authorities, and other stakeholders concerning potential cybersecurity vulnerabilities or security incidents affecting BAUER products.

Manufacturer: BAUER Maschinen GmbH, BAUER-Straße 1, 86529 Schrobenhausen

Security Contact

If you believe you have identified a cybersecurity vulnerability or a security incident affecting a BAUER product, including a vulnerability in a third-party or open-source component integrated into a BAUER product, please contact us: 

BMA-Security@bauer.de

Submit a Security Report

Please do not include personal data, confidential customer data, or safety-critical operational data unless strictly necessary for understanding the reported issue. If sensitive information is required, please indicate this in your initial message so that BAUER can agree on an appropriate exchange method.

What You Can Report

Reporting Channels by Stakeholder

Customers and Users

Customers and users should report suspected cybersecurity incidents, suspicious product behavior, potential vulnerability exploitation, or other cyber-related concerns affecting BAUER products.

Suppliers and Service Providers

Suppliers and service providers should report vulnerabilities, exploitation information, advisories, security incidents, or lifecycle changes affecting supplied components, software, services, or documentation.

Security Researchers and White-Hat Hackers

Security researchers are encouraged to report findings responsibly and to coordinate disclosure with BAUER before publishing details.

Authorities and Coordinators

Authorities and designated coordination bodies may use this contact point to reach BAUER regarding product cybersecurity matters.

Information to Include in Your Report

To help BAUER assess and respond efficiently, please include as much of the following information as possible:
 

Product Information

  • Product name and product family
  • Product model or type
  • Serial number, if applicable
  • Software, firmware, or configuration version
  • Affected component, interface, module, or function

     

Issue Description

  • Clear description of the vulnerability or incident
  • Date and time of discovery
  • Observed or expected security impact
  • Whether exploitation is suspected or confirmed
  • Whether the issue affects a BAUER product in operation

     

Technical Evidence

  • Steps to reproduce, if safely possible
  • Logs, screenshots, traces, or error messages
  • Proof-of-concept information, if appropriate
  • Network captures or indicators of compromise, if available
  • Relevant CVE, advisory, or supplier reference

Coordinated Vulnerability Disclosure

BAUER supports coordinated vulnerability disclosure and appreciates responsible reports that help improve product security.

We ask security researchers to: 

  • Act in good faith and avoid actions that could endanger people, equipment, customer operations, or availability of systems.
  • Avoid unauthorized access to data, modification of data, service disruption, social engineering, physical attacks, or attacks against third-party systems.
  • Report the finding to BAUER before public disclosure and allow reasonable coordination for assessment and remediation.
  • Provide sufficient technical detail to allow BAUER to understand, reproduce, and assess the issue.

BAUER will: 

  • Acknowledge receipt of a security report within three business days. The acknowledgement confirms receipt only and does not constitute validation or acceptance of the reported vulnerability or incident.
  • Assess whether the report concerns a BAUER product, component, or related service.
  • Prioritize reports based on potential cybersecurity impact, safety implications, exploitability, and affected products.
  • Communicate with the reporter as appropriate during analysis and remediation, including an indicative target timeframe for remediation depending on severity.
  • Coordinate customer, supplier, authority, and regulatory communication where required.

Important: 

This page does not grant permission to conduct intrusive testing against BAUER systems, customer systems, operational environments, or production equipment. Any testing must comply with applicable law and must not create safety, security, availability, privacy, or operational risks.

Cyber Resilience Act Context

Reports submitted through this page may be used as inputs for BAUER's cybersecurity vulnerability handling, incident assessment, customer communication, supplier coordination, and regulatory assessment processes, including obligations related to the EU Cyber Resilience Act where applicable.

Reports concerning actively exploited vulnerabilities or severe incidents affecting the security of BAUER products will be evaluated according to BAUER's internal cybersecurity and regulatory reporting procedures.

https://equipment.bauer.de/.well-known/security.txt

Confidentiality and Data Protection

BAUER will handle reported information with appropriate confidentiality and use it for cybersecurity assessment, vulnerability handling, incident response, product security improvement, supplier coordination, customer communication, and applicable legal or regulatory obligations.

Please avoid sending unnecessary personal data. If your report contains personal data, BAUER will process it in accordance with applicable data protection requirements.

BAUER Product Security | Contact: BMA-Security@bauer.de

This page is intended for reporting cybersecurity vulnerabilities and security incidents affecting BAUER products. For general customer support requests, please use the regular BAUER customer support channels.

Last updated: 13 August 2026