ETSI · Vulnerability Disclosure

Etsi Vulnerability Disclosure

Vulnerability disclosure

ETSI publishes a vulnerability disclosure policy for reporting security issues. A dedicated security contact is published.

TelecommunicationsFranceStandardsStandards BodyNetwork APIsEdge ComputingMECNFV5GCAMARATM Forum3GPPCAPIFNGSI-LDIoTOpen SourceEuropeOpenAPINetwork SlicingBroadband
Program:

Disclosure Policy

Policy

Security Contact

Contact
ETSI_CVD@etsi.org

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-25'
method: searched
probe: true
source: https://www.etsi.org/standards/coordinated-vulnerability-disclosure/
program: ETSI Coordinated Vulnerability Disclosure (CVD)
policy:
- https://www.etsi.org/standards/coordinated-vulnerability-disclosure/
contact:
- ETSI_CVD@etsi.org
submission: online form on the Coordinated Vulnerability Disclosure page
scope: >-
  Vulnerabilities caused by errors, omissions or ambiguities in ETSI standards — that is, flaws
  in the specification itself, not in a vendor's implementation of it. ETSI states explicitly
  that it is responsible for writing and issuing Technical Specifications and is not responsible
  for proprietary equipment designed, built and tested to those specifications.
process:
- ETSI acknowledges every declaration received
- the report is routed to the ETSI Technical Group best placed to analyse and resolve it
- the reporter is notified when the vulnerability has been eliminated
- reports may be submitted anonymously; ETSI guarantees not to attempt to identify anonymous reporters
- non-anonymous reporters may opt to be publicly credited in ETSI's hall of fame
embargo: >-
  ETSI asks reporters not to share knowledge of the vulnerability with third parties until ETSI
  has resolved it, and not to exploit it beyond what is necessary to gather enough data to report it
bounty:
  offered: false
  note: ETSI is a not-for-profit association; CVD disclosures generate no financial compensation
hall_of_fame: true
security_txt:
  published: false
  note: no RFC 9116 /.well-known/security.txt on any ETSI host — see well-known/etsi-well-known.yml
related_standards:
- id: etsi-tr-103-838
  title: 'ETSI TR 103 838: Guide to Coordinated Vulnerability Disclosure'
  url: https://www.etsi.org/deliver/etsi_tr/103800_103899/103838/01.01.01_60/tr_103838v010101p.pdf
- id: etsi-en-303-645
  title: 'ETSI EN 303 645: Cyber Security for Consumer Internet of Things — mandates a vulnerability disclosure policy as provision 5.2-1'
  url: https://www.etsi.org/technologies/consumer-iot-security
evidence:
- source: https://www.etsi.org/standards/coordinated-vulnerability-disclosure/
  kind: disclosure-policy-page
  status: 200
- source: https://www.etsi.org/newsroom/press-releases/2029-2022-02-etsi-releases-report-on-coordinated-vulnerability-disclosure
  kind: press-release
note: >-
  The mechanical probe in 0-working/probe-security-programs.py reports vdp=none for etsi.org
  because www.etsi.org answers a bare curl with HTTP 403; the program is real and was confirmed
  with a browser user agent.