Inspur Cloud · Vulnerability Disclosure

Inspur Cloud Vulnerability Disclosure

Vulnerability disclosure

Inspur Cloud runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CloudInfrastructureComputeStorageNetworkingObject StorageIdentityDatabaseContainersInternet of ThingsBlockchainChinaCompany
Program: Hackerone

Disclosure Policy

Security Contact

Contact
emailsec@inspur.com
Contact
encryptionPGP
Contact
fingerprint9C0A 9271 6CF9 0CF6 8B28 0606 7CF5 0934 C483 FD05
Contact
key_id0xC483FD05

Source

Vulnerability Disclosure

inspur-cloud-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-23'
method: searched
source: https://www.inspur.com/lcjtww/2312126/2432763/index.html
note: 'Inspur Cloud does not run its own vulnerability disclosure programme. The programme
  belongs to Inspur Group''s PSIRT (Product Security Incident Response Team) on inspur.com,
  the parent company whose domain Inspur Cloud''s corporate site also sits under, and it
  covers "Inspur products" generally rather than the cloud platform specifically. Recorded
  here as the disclosure route a researcher would actually use, with that scope caveat
  stated. There is no /.well-known/security.txt on any Inspur host.'
program:
  exists: true
  operator: Inspur Group PSIRT
  scope: Inspur products (not scoped explicitly to the Inspur Cloud platform)
  url: https://www.inspur.com/lcjtww/2312126/2432763/index.html
  advisories_url: https://www.inspur.com/lcjtww/psirt/security-advisories/index.html
  probed:
  - url: https://www.inspur.com/lcjtww/2312126/2432763/index.html
    status: 200
  - url: https://www.inspur.com/lcjtww/psirt/security-advisories/index.html
    status: 200
contact:
  email: sec@inspur.com
  encryption: PGP
  key_id: '0xC483FD05'
  fingerprint: 9C0A 9271 6CF9 0CF6 8B28 0606 7CF5 0934 C483 FD05
submission_requirements:
- Reporter or organisation name and contact details
- Affected products and versions
- How the vulnerability was found, with detailed reproduction steps
- Proof of exploitation / PoC
- Suggested remediation
bug_bounty:
  exists: false
  detail: No monetary reward, HackerOne, Bugcrowd or Intigriti programme is referenced.
disclosure_policy:
  published: partial
  detail: 'A vulnerability response process document is linked from the reporting page, but
    no embargo period, acknowledgement SLA, or coordinated-disclosure timeline is stated on
    the public page.'
security_txt:
  served: false
  detail: /.well-known/security.txt returns 404 on cloud.inspur.com, console1.cloud.inspur.com
    and en.inspur.com (probed 2026-08-23).
advisory_track_record:
  publishes_advisories: true
  examples:
  - CVE-2024-1086 Linux kernel netfilter use-after-free privilege escalation
  - CVE-2021-30465 runc symlink-swap container escape
  - CVE-2020-11651 SaltStack unauthenticated remote command execution
  - Apache Log4j2 remote code execution
  - sudo privilege escalation
  note: 'The advisories are downstream OS/component notices for Inspur hardware and software
    products. No advisory specific to an Inspur Cloud API or platform service was found.'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/inspur-cloud-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.