SE050 vulnerability reporting

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

SE050 vulnerability reporting

78 Views
djdirkj
Contributor II

 

I have a technical support question regarding the SE050. We are bringing a product to market that uses the SE050, and this product will not receive software updates in the field. Under the EU Cyber Resilience Act (CRA), we have an obligation to monitor for vulnerabilities in the components we use and to report actively exploited vulnerabilities and severe incidents within the required timelines.

 

Could you tell us:

- Does NXP operate a vulnerability disclosure or security notification process for the SE050 (e.g. a mailing list, security advisories page, or PSIRT feed) that we could subscribe to or monitor?

- How are known vulnerabilities and their status (fixed, mitigated, not applicable) communicated to customers using the SE050, given that this specific product line does not support field updates?

- Is there a way to get proactive notifications rather than having to check manually?

Labels (1)
0 Kudos
Reply
1 Reply

41 Views
Kan_Li
NXP TechSupport
NXP TechSupport

Hi @djdirkj ,

 

[Product Security Vulnerability | NXP Semiconductors|https://www.nxp.com/support/support/product-security-vulnerability:PSIRT] PSIRT team can be reported of vulnerabilities, they evaluate, find apt solution and communicate to affected buyers of the product - direct customers and distis which then inform their buyers.

Errors and mitigiations are documented in errata sheet and user guidance. Anyone can receive updates of these documents by clicking the "receiving alerts" option on the website of the product page to get informed on document updates.

 

Have a great day,
Kan


-------------------------------------------------------------------------------
Note:
- If this post answers your question, please click the "Mark Correct" button. Thank you!
- We are following threads for 7 weeks after the last post, later replies are ignored
Please open a new thread and refer to the closed one, if you have a related question at a later point in time.
-------------------------------------------------------------------------------

0 Kudos
Reply
%3CLINGO-SUB%20id%3D%22lingo-sub-2399239%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3ESE050%20vulnerability%20reporting%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2399239%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CDIV%3E%3CP%20class%3D%22%22%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3C%2FDIV%3E%3CDIV%3E%3CP%20class%3D%22%22%3E%3CSPAN%3EI%20have%20a%20technical%20support%20question%20regarding%20the%20SE050.%20We%20are%20bringing%20a%20product%20to%20market%20that%20uses%20the%20SE050%2C%20and%20this%20product%20will%20not%20receive%20software%20updates%20in%20the%20field.%20Under%20the%20EU%20Cyber%20Resilience%20Act%20(CRA)%2C%20we%20have%20an%20obligation%20to%20monitor%20for%20vulnerabilities%20in%20the%20components%20we%20use%20and%20to%20report%20actively%20exploited%20vulnerabilities%20and%20severe%20incidents%20within%20the%20required%20timelines.%3C%2FSPAN%3E%3C%2FP%3E%3C%2FDIV%3E%3CDIV%3E%3CP%20class%3D%22%22%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3C%2FDIV%3E%3CDIV%3E%3CP%20class%3D%22%22%3E%3CSPAN%3ECould%20you%20tell%20us%3A%3C%2FSPAN%3E%3C%2FP%3E%3C%2FDIV%3E%3CDIV%3E%3CP%20class%3D%22%22%3E%3CSPAN%3E-%20Does%20NXP%20operate%20a%20vulnerability%20disclosure%20or%20security%20notification%20process%20for%20the%20SE050%20(e.g.%20a%20mailing%20list%2C%20security%20advisories%20page%2C%20or%20PSIRT%20feed)%20that%20we%20could%20subscribe%20to%20or%20monitor%3F%3C%2FSPAN%3E%3C%2FP%3E%3C%2FDIV%3E%3CDIV%3E%3CP%20class%3D%22%22%3E%3CSPAN%3E-%20How%20are%20known%20vulnerabilities%20and%20their%20status%20(fixed%2C%20mitigated%2C%20not%20applicable)%20communicated%20to%20customers%20using%20the%20SE050%2C%20given%20that%20this%20specific%20product%20line%20does%20not%20support%20field%20updates%3F%3C%2FSPAN%3E%3C%2FP%3E%3C%2FDIV%3E%3CDIV%3E%3CP%20class%3D%22%22%3E%3CSPAN%3E-%20Is%20there%20a%20way%20to%20get%20proactive%20notifications%20rather%20than%20having%20to%20check%20manually%3F%3C%2FSPAN%3E%3C%2FP%3E%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2399239%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CLINGO-LABEL%3ESE050%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2399807%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20SE050%20vulnerability%20reporting%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2399807%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F218188%22%20target%3D%22_blank%22%3E%40djdirkj%3C%2FA%3E%26nbsp%3B%2C%3C%2FP%3E%0A%3CBR%20%2F%3E%0A%3CP%3E%5BProduct%20Security%20Vulnerability%20%7C%20NXP%20Semiconductors%7C%3CA%20href%3D%22https%3A%2F%2Fwww.nxp.com%2Fsupport%2Fsupport%2Fproduct-security-vulnerability%3APSIRT%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.nxp.com%2Fsupport%2Fsupport%2Fproduct-security-vulnerability%3APSIRT%3C%2FA%3E%5D%20PSIRT%20team%20can%20be%20reported%20of%20vulnerabilities%2C%20they%20evaluate%2C%20find%20apt%20solution%20and%20communicate%20to%20affected%20buyers%20of%20the%20product%20-%20direct%20customers%20and%20distis%20which%20then%20inform%20their%20buyers.%20%3CBR%20%2F%3E%3CBR%20%2F%3EErrors%20and%20mitigiations%20are%20documented%20in%20errata%20sheet%20and%20user%20guidance.%20Anyone%20can%20receive%20updates%20of%20these%20documents%20by%20clicking%20the%20%22receiving%20alerts%22%20option%20on%20the%20website%20of%20the%20product%20page%20to%20get%20informed%20on%20document%20updates.%3C%2FP%3E%0A%3CBR%20%2F%3E%0A%3CP%3EHave%20a%20great%20day%2C%3CBR%20%2F%3EKan%3C%2FP%3E%0A%3CP%3E%3CBR%20%2F%3E-------------------------------------------------------------------------------%3CBR%20%2F%3ENote%3A%3CBR%20%2F%3E-%20If%20this%20post%20answers%20your%20question%2C%20please%20click%20the%20%22Mark%20Correct%22%20button.%20Thank%20you!%3CBR%20%2F%3E-%20We%20are%20following%20threads%20for%207%20weeks%20after%20the%20last%20post%2C%20later%20replies%20are%20ignored%3CBR%20%2F%3EPlease%20open%20a%20new%20thread%20and%20refer%20to%20the%20closed%20one%2C%20if%20you%20have%20a%20related%20question%20at%20a%20later%20point%20in%20time.%3CBR%20%2F%3E-------------------------------------------------------------------------------%3C%2FP%3E%3C%2FLINGO-BODY%3E