Carrier Global · Vulnerability Disclosure
Carrier Global Vulnerability Disclosure
Vulnerability disclosure
Carrier Global runs a coordinated vulnerability disclosure program on Hackerone.
HVACCold ChainTelematicsBuilding AutomationIoTRefrigerationFortune 500
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-09-05'
method: searched
source: https://www.carrier.com/us/en/product-security/report-an-issue.html
provider: Carrier Global
providerId: carrier-global
program:
name: Carrier Product Security Incident Response Team (PSIRT)
published: true
url: https://www.carrier.com/us/en/product-security/report-an-issue.html
http_status: 200
policy_url: https://www.carrier.com/us/en/product-security/report-an-issue.html
advisories_url: https://www.carrier.com/us/en/product-security/advisories.html
program_overview_url: https://www.carrier.com/us/en/product-security.html
bug_bounty: false
bounty_platform: none
evidence:
- url: https://hackerone.com/carrier
status: 404
- url: https://bugcrowd.com/carrier
status: 404
scope: >-
"Carrier encourages reporters, including security researchers, end-users, and
vendors, to contact us with any information relating to potential security flaws or
vulnerabilities within any of our offerings." The advisories index covers Automated
Logic WebCTRL, Carrier i-Vu, Carrier and Automated Logic zone controllers, Viessmann
Vitogate 300 and Carrier-wide responses to third-party CVEs (MOVEit, Log4j,
Spring4Shell, Text4Shell, OpenSSL 3.0, Apache Shiro, Okta/Lapsus$).
disclosure_model: coordinated
disclosure_statement: >-
"The Carrier Product Security Incident Response Team (PSIRT) employs a coordinated
approach to vulnerability disclosure and publication. PSIRT determines the best path
when issuing security advisories for our supported Carrier [offerings]."
mission_statement: >-
"Carrier endeavors to ensure that validation, analysis, and mitigation of findings
are proactively communicated in a responsible manner. The Carrier PSIRT Plan
prepares and discloses product security advisory publications to acknowledge the
reporters, vulnerabilities, impacts, and mitigations of the reported incidents."
acknowledgement_sla: Receipt of issue/concern notification will be provided within 48 hours.
reporter_credit: >-
Advisories are stated to acknowledge the reporters, so researcher credit is part of
the published process.
cna: true
cna_evidence: >-
Carrier states it serves as a "CVE Numbering Authority (CNA)" on
https://www.carrier.com/us/en/product-security.html, and its advisories carry
CVE identifiers it has assigned (e.g. CVE-2024-8525/8526/8527/8528, CVE-2025-9494/9495,
CVE-2026-24060/25086/32666).
reporting:
channels:
- kind: web-form
url: https://www.carrier.com/us/en/product-security/report-an-issue.html
fields_requested:
- Software / Firmware / Hardware version
- Description of issue / concern (required)
- Reproduction steps (required)
- kind: encrypted-email
preferred: true
note: >-
"Preferred Secure Reporting Method: Encrypted Content (PGP). For sensitive
vulnerability details, please encrypt your message using OpenPGP (PGP) before
sending email." Carrier publishes both full instructions and the public key for
download from the same page.
pgp:
published: true
fingerprint: 8744 2AB6 27A4 EAB6 A82F 798D 5ED7 A15E 6180 7FB6
note: >-
Fingerprint transcribed verbatim from the published page. The key itself is
offered as a download link on that page and is not mirrored here.
postal_address: 13995 Pasteur Blvd. Palm Beach Gardens, FL 33418
security_txt:
published: false
note: >-
Carrier runs a full PSIRT with a published PGP key and a coordinated disclosure
policy but does NOT publish /.well-known/security.txt on any of its hosts — the
single cheapest thing it could do to make this program machine-discoverable. See
well-known/carrier-global-well-known.yml for the probe record.
alliances:
- Founding Member of the ISA Global Cybersecurity Alliance
maintainers:
- FN: Kin Lane
email: info@apievangelist.com
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/carrier-global-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.