Skip to content

Security: Siemens-Healthineers/SHIELD-DAVE

Security

SECURITY.md

Security Policy

Overview

The Device Assessment and Vulnerability Exposure (DAVE) project takes security seriously. As a platform designed to manage medical device cybersecurity and vulnerability tracking for healthcare organizations, we are committed to maintaining the highest security standards and responding promptly to security concerns.

How To Report a Vulnerability

If you think you have found a vulnerability in this repository, please report it to us through coordinated disclosure.

Please do not report security vulnerabilities through public issues, discussions, or change requests.

Instead, report it using one of the following ways:

Please include as much of the information listed below as you can to help us better understand and resolve the issue:

  • Type of issue: (e.g., SQL injection, cross-site scripting, authentication bypass, privilege escalation)
  • Affected version(s): Which version(s) of DAVE are affected
  • Impact: Description of the security impact, including how an attacker might exploit the issue
  • Affected component: Which part of DAVE is affected (web interface, API, background services, database, etc.)
  • Reproduction steps: Step-by-step instructions to reproduce the vulnerability
  • Source code location: Tag/branch/commit or direct URL to the affected code
  • Configuration details: Any special configuration required to reproduce the issue
  • Proof-of-concept: Code or detailed description demonstrating the vulnerability (if available)
  • Suggested fix: If you have suggestions for how to fix the issue (optional)
  • Public disclosure timeline: If you plan to publicly disclose the vulnerability, please let us know the timeline

This information will help us triage and address your report more quickly.

Thank You

We appreciate the security research community's efforts in helping keep DAVE and its users safe. Thank you for your responsible disclosure and collaboration in improving the security of healthcare device management.

There aren't any published security advisories