Report a Cybersecurity Vulnerability or Security Incident
BAUER welcomes reports from customers, users, suppliers, service providers, security researchers, white-hat hackers, authorities, and other stakeholders concerning potential cybersecurity vulnerabilities or security incidents affecting BAUER products.
Security Contact
If you believe you have identified a cybersecurity vulnerability or a security incident affecting a BAUER product, please contact us:
security@bauer.de
Please do not include personal data, confidential customer data, or safety-critical operational data unless strictly necessary for understanding the reported issue. If sensitive information is required, please indicate this in your initial message so that BAUER can agree on an appropriate exchange method.
What You Can Report
Reporting Channels by Stakeholder
Customers and users should report suspected cybersecurity incidents, suspicious product behavior, potential vulnerability exploitation, or other cyber-related concerns affecting BAUER products.
Suppliers and service providers should report vulnerabilities, exploitation information, advisories, security incidents, or lifecycle changes affecting supplied components, software, services, or documentation.
Security researchers are encouraged to report findings responsibly and to coordinate disclosure with BAUER before publishing details.
Authorities and designated coordination bodies may use this contact point to reach BAUER regarding product cybersecurity matters.
Information to Include in Your Report
To help BAUER assess and respond efficiently, please include as much of the following information as possible:
Product Information
- Product name and product family
- Product model or type
- Serial number, if applicable
- Software, firmware, or configuration version
Affected component, interface, module, or function
Issue Description
- Clear description of the vulnerability or incident
- Date and time of discovery
- Observed or expected security impact
- Whether exploitation is suspected or confirmed
Whether the issue affects a BAUER product in operation
Technical Evidence
- Steps to reproduce, if safely possible
- Logs, screenshots, traces, or error messages
- Proof-of-concept information, if appropriate
- Network captures or indicators of compromise, if available
- Relevant CVE, advisory, or supplier reference
Coordinated Vulnerability Disclosure
BAUER supports coordinated vulnerability disclosure and appreciates responsible reports that help improve product security.
We ask security researchers to:
- Act in good faith and avoid actions that could endanger people, equipment, customer operations, or availability of systems.
- Avoid unauthorized access to data, modification of data, service disruption, social engineering, physical attacks, or attacks against third-party systems.
- Report the finding to BAUER before public disclosure and allow reasonable coordination for assessment and remediation.
- Provide sufficient technical detail to allow BAUER to understand, reproduce, and assess the issue.
BAUER will:
- Acknowledge receipt of reports sent to the security contact. Assess whether the report concerns a BAUER product, component, or related service.
- Prioritize reports based on potential cybersecurity impact, safety implications, exploitability, and affected products.
- Communicate with the reporter as appropriate during analysis and remediation.
- Coordinate customer, supplier, authority, and regulatory communication where required.
Important:
This page does not grant permission to conduct intrusive testing against BAUER systems, customer systems, operational environments, or production equipment. Any testing must comply with applicable law and must not create safety, security, availability, privacy, or operational risks. Cyber Resilience Act Context
Cyber Resilience Act Context
Reports submitted through this page may be used as inputs for BAUER's cybersecurity vulnerability handling, incident assessment, customer communication, supplier coordination, and regulatory assessment processes, including obligations related to the EU Cyber Resilience Act where applicable.
Reports concerning actively exploited vulnerabilities or severe incidents affecting the security of BAUER products will be evaluated according to BAUER's internal cybersecurity and regulatory reporting procedures.
Encrypted Reporting with OpenPGP
If your report contains sensitive technical information, you may encrypt the message or attachments with the BAUER Product Security OpenPGP public key before sending them to security@bauer.de.
BAUER Product Security public key:
Download the OpenPGP public key
Fingerprint: TO BE INSERTED AFTER KEY GENERATION
Before encrypting a report
- Download the public key only from the official BAUER website.
- Verify the complete fingerprint shown above against the fingerprint displayed by your OpenPGP software.
- Encrypt the report and attachments to the BAUER Product Security public key.
- Do not encrypt the email subject. Use a neutral subject such as “BAUER Product Security Report”.
Only the public key is published. The corresponding private key is retained by BAUER and must never be shared.
Languages
Security reports may be submitted in English or German.
Confidentiality and Data Protection
BAUER will handle reported information with appropriate confidentiality and use it for cybersecurity assessment, vulnerability handling, incident response, product security improvement, supplier coordination, customer communication, and applicable legal or regulatory obligations.
Please avoid sending unnecessary personal data. If your report contains personal data, BAUER will process it in accordance with applicable data protection requirements.
Machine-Readable Security Contact
BAUER also publishes machine-readable security contact information via /.well-known/security.txt to help security researchers and automated tools find the correct reporting channel.
BAUER Product Security | Contact: security@bauer.de
This page is intended for reporting cybersecurity vulnerabilities and security incidents affecting BAUER products. For general customer support requests, please use the regular BAUER customer support channels.
Last updated: 13 August 2026