Cisco Crosswork · Vulnerability Disclosure

Cisco Crosswork Vulnerability Disclosure

Vulnerability disclosure

Cisco Crosswork runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

Network AutomationService ProvidersOrchestrationNetworkingAssuranceTelecommunicationsRESTCONFYANGZero Touch ProvisioningWorkflow AutomationTraffic EngineeringMCPTelemetryOn-Premises
Program: Hackerone

Disclosure Policy

Policy
Policy

Security Contact

Contact
emailpsirt@cisco.com
Contact
pgp_fingerprint081e38f3eb110265a214514124b3ec61e4205802
Contact
pgp_keyhttps://cscrdr.cloudapps.cisco.com/cscrdr/security/center/files/Cisco_PSIRT_PGP_Public_Key.asc
Contact
sourcesecurity.txt Contact field

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-19'
method: probed
source: https://www.cisco.com/.well-known/security.txt
name: Cisco Product Security Incident Response Team (PSIRT)
published: true
program:
  type: coordinated-disclosure
  operator: Cisco PSIRT
  scope: >-
    All Cisco products and cloud services, which includes the Cisco Crosswork portfolio (Network Controller, Data
    Gateway, Zero Touch Provisioning, Optimization Engine, Workflow Manager).
  bug_bounty: false
  bug_bounty_note: >-
    No HackerOne, Bugcrowd or Intigriti program was found for Cisco Crosswork. Cisco runs coordinated disclosure
    through PSIRT rather than a public bounty platform.
contact:
  email: psirt@cisco.com
  source: security.txt Contact field
  pgp_key: https://cscrdr.cloudapps.cisco.com/cscrdr/security/center/files/Cisco_PSIRT_PGP_Public_Key.asc
  pgp_fingerprint: 081e38f3eb110265a214514124b3ec61e4205802
policy:
  url: https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html
  source: security.txt Policy field
advisories:
  machine_readable: true
  format: CSAF 2.0
  role: csaf_trusted_provider
  provider_metadata: https://www.cisco.com/.well-known/csaf/provider-metadata.json
  directory: https://www.cisco.com/.well-known/csaf/
  note: >-
    Cisco is a CSAF trusted provider and publishes its security advisories as machine-readable CSAF documents. This
    is a materially stronger disclosure posture than a contact address alone: an agent can consume the advisory feed
    without scraping.
security_txt:
  served: true
  url: https://www.cisco.com/.well-known/security.txt
  file: well-known/cisco-crosswork-security.txt
  signed: true
  signature: PGP clear-signed
  expires: '2027-01-01T00:00:00.000Z'
x-evidence:
- url: https://www.cisco.com/.well-known/security.txt
  http_status: 200
  content_type: text/plain
- url: https://www.cisco.com/.well-known/csaf/provider-metadata.json
  http_status: 200
  content_type: application/json
- url: https://developer.cisco.com/.well-known/security.txt
  http_status: 404
  note: The Crosswork documentation host does not serve its own security.txt; the corporate host does.
checked: '2026-08-19'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/cisco-crosswork-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.