EMC · Vulnerability Disclosure

Emc Vulnerability Disclosure

Vulnerability disclosure

EMC (Dell EMC) vulnerability disclosure runs through Dell Technologies' PSIRT. An RFC 9116 security.txt is served at www.dell.com and names two separate Bugcrowd bug bounty programs — one for Dell's web applications, one for Dell products, which is the one that covers the EMC storage platforms. A PGP key for encrypted submissions is published.

EMC runs a coordinated vulnerability disclosure program on Bugcrowd. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

Cloud InfrastructureData ManagementData ProtectionEnterprise StorageObject StorageStorageS3 CompatibleFortune 500
Program: Bugcrowd security.txt present

Disclosure Policy

Policy

Security Contact

Contact
https://bugcrowd.com/dell-com
Contact
https://bugcrowd.com/dell-product
Contact
https://www.dell.com/support/dell-vulnerability-response-policy

Source

Vulnerability Disclosure

emc-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-29'
method: searched
probe: true
source: https://www.dell.com/.well-known/security.txt
provider: EMC
providerId: emc
description: >-
  EMC (Dell EMC) vulnerability disclosure runs through Dell Technologies' PSIRT. An RFC
  9116 security.txt is served at www.dell.com and names two separate Bugcrowd bug bounty
  programs — one for Dell's web applications, one for Dell products, which is the one that
  covers the EMC storage platforms. A PGP key for encrypted submissions is published.
policy:
  - https://www.dell.com/support/dell-vulnerability-response-policy
contact:
  - https://bugcrowd.com/dell-com
  - https://bugcrowd.com/dell-product
  - https://www.dell.com/support/dell-vulnerability-response-policy
bug_bounty:
  operated: true
  platform: Bugcrowd
  programs:
    - name: Dell Bug Bounty Program — Applications
      url: https://bugcrowd.com/dell-com
      http_status: 200
      scope: Dell web applications
    - name: Dell Bug Bounty Program — Products
      url: https://bugcrowd.com/dell-product
      http_status: 200
      scope: Dell products, including the EMC storage platforms
encryption_key: https://www.delltechnologies.com/asset/en-us/products/security/legal-pricing/dell-psirt-pub-key.txt
canonical: https://www.dell.com/.well-known/security.txt
hiring: https://jobs.dell.com/search-jobs/sro
security_advisories: https://www.dell.com/support/security/en-us/
expires: '2026-04-17T04:00:00.000Z'
expired: true
finding: >-
  The security.txt is real and complete but EXPIRED. Its Expires field reads
  2026-04-17T04:00:00.000Z and its own trailing comment dates the file to 17 April 2025;
  as of this probe on 2026-08-29 it is more than four months past its stated validity.
  RFC 9116 section 2.5.5 requires the Expires date be in the future, so a strict consumer
  should treat the document as stale. Everything it points at is still live — this is a
  refresh Dell has not run, not a programme that has lapsed.
evidence:
  - url: https://www.dell.com/.well-known/security.txt
    status: 200
    kind: security.txt (live probe, saved verbatim to well-known/emc-security.txt)
  - url: https://bugcrowd.com/dell-com
    status: 200
    kind: bug bounty program page
  - url: https://www.dell.com/support/dell-vulnerability-response-policy
    status: 403
    kind: >-
      vulnerability response policy — Dell's support domain returns 403 to non-browser
      clients even with a browser User-Agent. This is an edge bot policy, not a dead page;
      the URL is the Canonical target named in Dell's own security.txt.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/emc-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.