Security Advisories
Lawo is committed to the highest standards of security across its product portfolio. These standards are addressed and maintained as part of the product lifecycle process — from secure development practices and code review, through extensive pre-release testing, to continuous monitoring of newly disclosed vulnerabilities affecting both Lawo's own software and the third-party and open-source components it incorporates. Where an issue is identified it is isolated, assessed for severity, and remediated in a scheduled release or, where the risk warrants it, in a hotfix.
Lawo's Product Security Incident Response Team (PSIRT) provides coverage for the public reporting of possible security vulnerabilities across the entire Lawo product portfolio. This spans IP audio, video and control — including audio consoles, audio and video processing as well as the control, orchestration and management software that runs alongside them. In addition to receiving reports, the PSIRT is responsible for notifying customers of confirmed vulnerabilities in a timely manner, publishing security advisories that identify the affected products and versions, assess the severity of the issue, and set out the update or workaround that resolves it.
The PSIRT monitors industry-wide vulnerability reporting and acts as a single point of contact for customers and interested third parties to investigate and identify potential threats. Customers are kept informed of issues affecting the products they operate and are given the detail needed to assess the risk to their own environments.
For technical assistance with the workarounds and hotfix installations recommended in security advisories, customers and interested third parties should raise a request through the Lawo Customer Service Portal using the "Security Request" option.
The security support a Lawo product receives depends on its current lifecycle status. Advisories identify the affected releases and the versions in which a remedy is available; products that have reached end-of-life status are no longer eligible for security fixes. Lifecycle status and end-of-life dates for individual Lawo products are published in the Product Support area of the Lawo website.
Report security vulnerabilities found in Lawo products to the PSIRT via psirt@lawo.com. To ensure secure and private communication directly with the team, use of Lawo's PGP key is recommended. The key fingerprint is FCC6 04F3 65C0 EF90 88CF 4C8A 6CBF 2E03 AF19 A5EF
Lawo PSIRT is happy to work with researchers who report vulnerabilities in Lawo products, including on CVE assignment and disclosure timelines, and will acknowledge them in the resulting advisory. Reports are welcome on both Lawo's own code and the open-source software used within Lawo products. Issues in open-source software that do not affect Lawo products fall outside Lawo's scope and should be referred to the appropriate CNA, listed here.
Lawo PSIRT Security Advisories
Lawo security advisories, and any materials they reference, are published on an “as is” basis and are used at your own risk. Lawo may change or update an advisory at any time and without notice.
Security Advisory 0002 |
|---|
Security Advisory 0001 |
To sign up for Lawo Security Advisory notifications, please register here
Lawo's vulnerability management process and best practice guidelines are listed here