The Device Assessment and Vulnerability Exposure (DAVE) project takes security seriously. As a platform designed to manage medical device cybersecurity and vulnerability tracking for healthcare organizations, we are committed to maintaining the highest security standards and responding promptly to security concerns.
If you think you have found a vulnerability in this repository, please report it to us through coordinated disclosure.
Please do not report security vulnerabilities through public issues, discussions, or change requests.
Instead, report it using one of the following ways:
-
Any vulnerability information MUST be sent using Encrypted Communication. Please use the public key with fingerprint: 729B B5CB A5CC 454D 70F3 EC3B E66C 158A 1EE1 904F
-
Email: Contact the project security team at projectshield.team@siemens-healthineers.com
Please include as much of the information listed below as you can to help us better understand and resolve the issue:
- Type of issue: (e.g., SQL injection, cross-site scripting, authentication bypass, privilege escalation)
- Affected version(s): Which version(s) of DAVE are affected
- Impact: Description of the security impact, including how an attacker might exploit the issue
- Affected component: Which part of DAVE is affected (web interface, API, background services, database, etc.)
- Reproduction steps: Step-by-step instructions to reproduce the vulnerability
- Source code location: Tag/branch/commit or direct URL to the affected code
- Configuration details: Any special configuration required to reproduce the issue
- Proof-of-concept: Code or detailed description demonstrating the vulnerability (if available)
- Suggested fix: If you have suggestions for how to fix the issue (optional)
- Public disclosure timeline: If you plan to publicly disclose the vulnerability, please let us know the timeline
This information will help us triage and address your report more quickly.
We appreciate the security research community's efforts in helping keep DAVE and its users safe. Thank you for your responsible disclosure and collaboration in improving the security of healthcare device management.