EnerSys · Vulnerability Disclosure

Enersys Vulnerability Disclosure

Vulnerability disclosure

EnerSys operates a public product-security disclosure surface: a "Common Vulnerabilities and Exposures (CVE) Disclosures" page under About Us > Quality that publishes advisories for vulnerabilities affecting EnerSys products, each linked to a PDF advisory. The page states the company follows responsible disclosure practices, but it publishes NO intake channel — no security@ address, no PSIRT contact, no reporting form, and no /.well-known/security.txt on any EnerSys host. This is a disclosure OUTPUT surface without a documented disclosure INPUT path.

EnerSys runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

EnergyBatteriesIndustrialEnergy StorageFortune 1000
Program: Hackerone

Disclosure Policy

Policy
Policy
Policy
Policy

Security Contact

Contact
fallbackhttps://www.enersys.com/en/contact-us/
Contact
noteNo reporting email, PSIRT alias, form or bug-bounty program is published on the CVE disclosures page or anywhere else found on enersys.com. The only routing offered is the general "Contact Us" form.
Contact
publishedfalse

Source

Vulnerability Disclosure

enersys-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-06'
method: searched
probe: true
source: https://www.enersys.com/en/about-us/quality/cve-disclosures/
provider: EnerSys
providerId: enersys
description: >-
  EnerSys operates a public product-security disclosure surface: a "Common Vulnerabilities and
  Exposures (CVE) Disclosures" page under About Us > Quality that publishes advisories for
  vulnerabilities affecting EnerSys products, each linked to a PDF advisory. The page states the
  company follows responsible disclosure practices, but it publishes NO intake channel — no
  security@ address, no PSIRT contact, no reporting form, and no /.well-known/security.txt on any
  EnerSys host. This is a disclosure OUTPUT surface without a documented disclosure INPUT path.
policy:
  published: true
  url: https://www.enersys.com/en/about-us/quality/cve-disclosures/
  statement: >-
    "We follow responsible disclosure practices and collaborate with security researchers and
    third-party experts to ensure vulnerabilities are addressed swiftly and effectively."
  scope: EnerSys products (advisories name affected product models)
contact:
  published: false
  note: >-
    No reporting email, PSIRT alias, form or bug-bounty program is published on the CVE
    disclosures page or anywhere else found on enersys.com. The only routing offered is the
    general "Contact Us" form.
  fallback: https://www.enersys.com/en/contact-us/
security_txt:
  served: false
  note: /.well-known/security.txt returns 404 on enersys.com, www.enersys.com, bsp.enersys.com, mptools.enersys.com and xinx.enersys.com.
bug_bounty:
  program: none
  note: No HackerOne, Bugcrowd or Intigriti program found for EnerSys.
advisories:
  - cve: CVE-2024-11861
    title: Web Interface Vulnerability
    affected_products:
      - XM3.1-HP 910-918
      - XM3.1-HP 903-905
      - SMG-HP
      - ADOM
    posted: '2025-05-09'
    advisory: https://www.enersys.com/4996bf/globalassets/documents/corporate/cve/enersys_cve-2024-11861-final.pdf
  - cve: CVE-2024-12442
    title: Single Webpage (Network Diagnostics) RCE Vulnerability
    affected_products:
      - XM3.1-HP 910-918
      - XM3.1-HP 903-905
      - SMG-HP
      - ADOM
    posted: '2025-05-09'
    advisory: https://www.enersys.com/4996df/globalassets/documents/corporate/cve/enersys_cve-2024-12442-final.pdf
evidence:
  - source: https://www.enersys.com/en/about-us/quality/cve-disclosures/
    kind: product security disclosure page (live fetch)
    http_status: 200
    fetched: '2026-09-06'
    keywords:
      - responsible disclosure
      - cybersecurity vulnerabilities
      - CVE
gaps:
  - No published vulnerability-reporting contact or intake channel.
  - No /.well-known/security.txt (RFC 9116) on any EnerSys host.
  - No stated coordinated-disclosure timeline or safe-harbor language.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/enersys-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.