Carrier Global · Vulnerability Disclosure

Carrier Global Vulnerability Disclosure

Vulnerability disclosure

Carrier Global runs a coordinated vulnerability disclosure program on Hackerone.

HVACCold ChainTelematicsBuilding AutomationIoTRefrigerationFortune 500
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-05'
method: searched
source: https://www.carrier.com/us/en/product-security/report-an-issue.html
provider: Carrier Global
providerId: carrier-global
program:
  name: Carrier Product Security Incident Response Team (PSIRT)
  published: true
  url: https://www.carrier.com/us/en/product-security/report-an-issue.html
  http_status: 200
  policy_url: https://www.carrier.com/us/en/product-security/report-an-issue.html
  advisories_url: https://www.carrier.com/us/en/product-security/advisories.html
  program_overview_url: https://www.carrier.com/us/en/product-security.html
  bug_bounty: false
  bounty_platform: none
  evidence:
    - url: https://hackerone.com/carrier
      status: 404
    - url: https://bugcrowd.com/carrier
      status: 404
  scope: >-
    "Carrier encourages reporters, including security researchers, end-users, and
    vendors, to contact us with any information relating to potential security flaws or
    vulnerabilities within any of our offerings." The advisories index covers Automated
    Logic WebCTRL, Carrier i-Vu, Carrier and Automated Logic zone controllers, Viessmann
    Vitogate 300 and Carrier-wide responses to third-party CVEs (MOVEit, Log4j,
    Spring4Shell, Text4Shell, OpenSSL 3.0, Apache Shiro, Okta/Lapsus$).
  disclosure_model: coordinated
  disclosure_statement: >-
    "The Carrier Product Security Incident Response Team (PSIRT) employs a coordinated
    approach to vulnerability disclosure and publication. PSIRT determines the best path
    when issuing security advisories for our supported Carrier [offerings]."
  mission_statement: >-
    "Carrier endeavors to ensure that validation, analysis, and mitigation of findings
    are proactively communicated in a responsible manner. The Carrier PSIRT Plan
    prepares and discloses product security advisory publications to acknowledge the
    reporters, vulnerabilities, impacts, and mitigations of the reported incidents."
  acknowledgement_sla: Receipt of issue/concern notification will be provided within 48 hours.
  reporter_credit: >-
    Advisories are stated to acknowledge the reporters, so researcher credit is part of
    the published process.
  cna: true
  cna_evidence: >-
    Carrier states it serves as a "CVE Numbering Authority (CNA)" on
    https://www.carrier.com/us/en/product-security.html, and its advisories carry
    CVE identifiers it has assigned (e.g. CVE-2024-8525/8526/8527/8528, CVE-2025-9494/9495,
    CVE-2026-24060/25086/32666).
reporting:
  channels:
    - kind: web-form
      url: https://www.carrier.com/us/en/product-security/report-an-issue.html
      fields_requested:
        - Software / Firmware / Hardware version
        - Description of issue / concern (required)
        - Reproduction steps (required)
    - kind: encrypted-email
      preferred: true
      note: >-
        "Preferred Secure Reporting Method: Encrypted Content (PGP). For sensitive
        vulnerability details, please encrypt your message using OpenPGP (PGP) before
        sending email." Carrier publishes both full instructions and the public key for
        download from the same page.
  pgp:
    published: true
    fingerprint: 8744 2AB6 27A4 EAB6 A82F 798D 5ED7 A15E 6180 7FB6
    note: >-
      Fingerprint transcribed verbatim from the published page. The key itself is
      offered as a download link on that page and is not mirrored here.
  postal_address: 13995 Pasteur Blvd. Palm Beach Gardens, FL 33418
security_txt:
  published: false
  note: >-
    Carrier runs a full PSIRT with a published PGP key and a coordinated disclosure
    policy but does NOT publish /.well-known/security.txt on any of its hosts — the
    single cheapest thing it could do to make this program machine-discoverable. See
    well-known/carrier-global-well-known.yml for the probe record.
alliances:
  - Founding Member of the ISA Global Cybersecurity Alliance
maintainers:
  - FN: Kin Lane
    email: info@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/carrier-global-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.