Our commitment

Lawo designs and manufactures IP audio, video and control products — including audio consoles, audio and video processing technologies — for live media production. Our products sit at the core of broadcast and live production facilities, often carrying content that cannot be interrupted and operating on networks that connect to wider enterprise and public infrastructure. Product security is therefore a functional requirement, not an add-on.

Lawo is committed to the highest standards of security across its product portfolio. These standards are addressed and maintained as part of the product lifecycle process — from secure development practices and code review, through extensive pre-release testing, to continuous monitoring of newly disclosed vulnerabilities affecting both Lawo's own software and the third-party and Open Source components it incorporates. Where an issue is identified, it is isolated, assessed for severity, and remediated in a scheduled release or, where the risk warrants it, in a hotfix.

This page describes how Lawo receives, assesses, remediates and discloses security vulnerabilities in its products. It is intended for customers, system integrators, security researchers, and the security teams of the broadcasters and production facilities that operate our equipment.

How our PSIRT is organised

Lawo PSIRT operates a distributed model with centralised triage and disclosure, aligned with the FIRST PSIRT Services Framework v1.1. A small central team — PSIRT Operations — owns intake, triage, CVSS scoring, advisory drafting, CVE coordination, regulator notification and disclosure. It works with a matrix of product security engineering representatives embedded in each product team, who carry out technical validation, reproduction and impact analysis, alongside the product owner and engineering team responsible for remediation and fix delivery.

PSIRT Operations has executive sponsorship from R&D leadership, giving it authority over remediation timelines across the distributed product teams rather than relying on the co-operation of teams outside its reporting line.

Standards and frameworks

Lawo's vulnerability handling process is aligned with:

  • ISO/IEC 29147 — Information technology, Security techniques, Vulnerability disclosure
  • ISO/IEC 30111 — Information technology, Security techniques, Vulnerability handling processes
  • FIRST PSIRT Services Framework v1.1 — organisational model and service scope
  • CVSS v4.0 (Common Vulnerability Scoring System) for severity assessment, with v3.1 scores provided where required for customer tooling compatibility
  • EU Cyber Resilience Act (Regulation (EU) 2024/2847) — see EU Cyber Resilience Act reporting below

Lawo is not a CVE Numbering Authority. Where a vulnerability in a Lawo product warrants a CVE identifier, Lawo PSIRT coordinates assignment through the appropriate CNA — either the reporting researcher's own CNA, or MITRE acting as CNA of Last Resort.

Scope

In scope:

  • All Lawo hardware products under active support, including — but not limited to — the mc² console range, diamond, crystal, Power Core, A__UHD Core, A__line, .edge, Edge One and associated I/O devices
  • Lawo software and platform products, including HOME, HOME Apps, Workspaces, VSM, VisTool, R3LAY, mxGUI and Kick
  • Embedded firmware, operating systems and bootloaders shipped by Lawo on Lawo hardware
  • Third-party and Open Source components incorporated into Lawo products, where the vulnerability is exploitable in the Lawo product as delivered

We continuously monitor the National Vulnerability Database (NVD), the Open Source Vulnerabilities database (OSV) and the GitHub Security Advisory Database (GHSA) against our products' software bills of materials (SBOM), so that vulnerable third-party and Open Source components are identified proactively rather than only when reported.

Out of scope:

  • Vulnerabilities in Open Source or third-party software that are not exploitable in a Lawo product as delivered. These should be reported to the upstream project or the relevant CNA.
  • Products that have reached end of support. Lawo's standard support period runs for five years from End of Production to End of Life. A list of supported products is published in the Product Support area of the Lawo website.
  • Lawo corporate websites, marketing sites and IT systems unrelated to product functionality. Please report these to info@lawo.com.
  • Findings that require physical disassembly of hardware in an attacker-controlled environment with no realistic operational equivalent, though we will still review these on their merits.
  • Denial of service achieved solely by traffic volume against a device operating outside its documented capacity limits.
  • Missing hardening measures with no demonstrable security impact, and findings produced by automated scanners without validation.

How to report a vulnerability

Send reports to psirt@lawo.com, or submit them through the Lawo Customer Service Portal using the 'Security Request' option.

Because vulnerability details are sensitive until remediated, we strongly recommend encrypting your report using the Lawo PSIRT PGP key:

KeyLawo PSIRT PGP key — also published and verified on keys.openpgp.org
Key ID6CBF2E03AF19A5EF
FingerprintFCC6 04F3 65C0 EF90 88CF 4C8A 6CBF 2E03 AF19 A5EF
Algorithm4096-bit RSA, SHA-512
CapabilitiesEncryption only — this key does not sign

The key is renewed annually. Please verify the fingerprint against this page before relying on a copy obtained elsewhere.

Reports may be submitted in English or German. English is preferred and will be handled fastest.

What to include

A report is easier to act on when it contains:

  1. Affected product and version — model or software name, firmware or software version, and where relevant the hardware revision
  2. Vulnerability type and description — what the weakness is and where it sits
  3. Reproduction steps — a clear sequence, with any tooling, configuration or network topology required
  4. Proof of concept — code, packet captures, screenshots or logs, as applicable
  5. Impact assessment — what an attacker gains, and any preconditions such as network position, authentication level or physical access
  6. Any proposed mitigation — anything you have identified
  7. Your details and disclosure intentions — how you wish to be credited, whether you intend to publish, and any planned publication date or conference deadline

Please do not include customer data, personal data, or content from third-party production systems in your report. If you encounter such data during research, stop, and tell us that you did so.

What we ask of reporters

  • Give us a reasonable opportunity to remediate before public disclosure
  • Do not access, modify or exfiltrate data belonging to Lawo customers
  • Do not degrade, disrupt or interrupt live production systems or services
  • Test only against equipment you own or are explicitly authorised to test
  • Do not use social engineering, physical intrusion, or attacks against Lawo staff or premises

Safe harbour

Lawo will not pursue or support legal action against researchers who discover and report vulnerabilities in good faith and in accordance with the expectations set out above. If a third party initiates action against a researcher who has complied with this policy, we will make that compliance known.

Lawo does not currently operate a paid bug bounty programme.

How we handle a report

Our process runs in five stages — report intake, triage, technical validation, remediation, and disclosure.

1. Acknowledgement

Lawo PSIRT acknowledges receipt of every report within 1–3 business days. Acknowledgement confirms receipt; it does not imply that a vulnerability has been validated.

2. Triage

PSIRT Operations establishes whether the report concerns a Lawo product and whether sufficient information is present to investigate, then assigns an initial CVSS score and determines ownership within the affected product team. Where information is missing we will come back to you. Target: 1–3 business days from acknowledgement.

3. Technical validation

The product security engineering representative for the affected product team reproduces the issue, determines the root cause, and identifies the full set of affected products and versions — including cases where the same component appears across multiple product lines. Severity is reassessed using CVSS as the picture becomes clearer, taking into account the operational reality of broadcast deployment, such as whether the affected interface is normally exposed on a control network, a media network, or an isolated management LAN.

4. Remediation

The product owner and engineering team develop and test a fix, mitigation or configuration workaround. Remediation timing is driven by severity:

Severity (CVSS)Target remediation
Critical (9.0–10.0)14–30 days, out-of-cycle release where required
High (7.0–8.9)60–90 days
Medium (4.0–6.9)Next scheduled maintenance release, at Lawo's discretion
Low (0.1–3.9)Next feature or maintenance release, at Lawo's discretion

Where a fix cannot be delivered inside the target window, we will document an interim mitigation and communicate the revised timeline to affected customers and to the reporter.

5. Disclosure

PSIRT Operations publishes a security advisory on the Security Advisories web-page when a fix or a documented mitigation is available, and notifies subscribers via the Security Advisories newsletter.

Each advisory states the affected products and versions, a description of the vulnerability, its CVSS score and vector, the CVE identifier where one has been assigned, the fixed version or mitigation, and — with their consent — credit to the reporter. PSIRT Operations also runs a post-mortem on each case and tracks disclosure metrics.

Lawo's coordinated disclosure window scales with severity:

SeverityCoordinated disclosure window
Critical90 days from acknowledgement
High120 days from acknowledgement
MediumAt Lawo's discretion, published with the release
LowAt Lawo's discretion, published with the release

We will publish sooner if a fix is ready earlier. We may publish earlier than the agreed date if the vulnerability is already being exploited, or if details have become public through another route. We may request an extension where a fix requires hardware changes, a coordinated upstream fix, or validation across a large product family; any such request will be made with reasoning and a proposed date.

EU Cyber Resilience Act reporting

Lawo's main establishment for the purposes of Regulation (EU) 2024/2847 is Rastatt, Germany. From 11th September 2026, Article 14 of the Cyber Resilience Act requires manufacturers to report two situations to the competent authorities:

  • An actively exploited vulnerability contained in the product (Article 14(1))
  • A severe incident having an impact on the security of the product (Article 14(3))

Both are reported through the CRA Single Reporting Platform to the coordinating CSIRT for Germany — CERT-Bund at the BSI — and, simultaneously, to ENISA, on a fixed clock from the point Lawo becomes aware: an early warning within 24 hours, a fuller notification within 72 hours, and a final report — 14 days after a corrective measure is available for a vulnerability, or one month after the 72-hour notification for an incident. Where required, affected users are informed separately, in addition to the regulatory notification.

The wider essential cybersecurity requirements of the Cyber Resilience Act, including secure-by-default and support-period obligations, apply from 11th December 2027. Lawo's processes are being aligned to both dates ahead of time. See the European Commission's guidance on CRA reporting obligations for further detail.

Notifying customers

Customers are notified of security advisories either by visiting the Security Advisories web-page or by registering for the Security Advisories newsletter. This applies equally to customers with an active SLA.

Acknowledging researchers

Researchers who report a valid, previously unknown vulnerability are credited in the resulting advisory, unless they ask to remain anonymous.

Reporting a suspected security incident

If you believe a Lawo product in your facility has been compromised, this is an incident rather than a vulnerability report. Contact Lawo Support immediately through the Lawo Customer Service Portal using the 'Security Request' option, or email psirt@lawo.com.

As with vulnerability reports, incident details are sensitive — we strongly recommend encrypting anything sent to psirt@lawo.com using the Lawo PSIRT PGP key (fingerprint FCC6 04F3 65C0 EF90 88CF 4C8A 6CBF 2E03 AF19 A5EF), particularly when the email includes evidence, logs, or details of the compromise.

Secure deployment guidance

Many risks in live production environments are reduced substantially by network design. Lawo publishes deployment and hardening guidance, including our IP Networking Guide, in the Lawo Knowledge Base. Product and technology training is also available through Lawo Academy.

Contact

PurposeContact
Report a product vulnerabilitypsirt@lawo.com
Encrypted submissionLawo PSIRT PGP key — fingerprint FCC6 04F3 65C0 EF90 88CF 4C8A 6CBF 2E03 AF19 A5EF
Published advisoriesSecurity Advisories web-page or the Security Advisories newsletter
Technical help with a fix or workaroundLawo Customer Service Portal
Suspected compromise of a Lawo productpsirt@lawo.com or the Lawo Customer Service Portal ('Security Request' option)
Corporate or website security issuesinfo@lawo.com