AVerMedia
  • 제품
    • 웹캠
      • 4K UHD
      • 1080 FULL HD
      • 키트
    • 캡쳐
      • 4K 캡쳐
      • 1080p60 캡쳐
      • AV / S Video 캡쳐
      • DSLR/ CAM모드 캡쳐
      • Video Converter
    • 오디오
      • 스피커폰
      • Soundbars
      • 마이크
      • 무선 마이크
      • 액세서리
    • 방송 컨트롤러
      • Creator Central
    • Video Bar
      • Mingle Bar
    • 스트리밍 확장 스테이션
      • 비디오 제품
      • 오디오 제품
    • 소프트웨어
      • 스트리밍 소프트웨어
  • 워크 스페이스
    • 워크 스페이스
      • 이달의 제품
      • 게임 스트리머
      • 비디오 콘텐츠 창작자
      • 재택근무
      • 교육용
      • 활용 가이드
      • 기업용
  • 고객지원
    • 고객지원
      • 다운로드&FAQ
      • 기술적 지원
      • 워런티&RMA 서비스
      • 구매처
      • 인증
  • 구매처
  • Store
  • 통합 AI 시스템
  • AVerMedia 소개
    • AVerMedia 소개
      • AVerMedia 소개
      • 연락처
      • 投資人關係
      • 기업의 사회적 책임
      • Recruiting
  • Account
  • Search
  • Language
  • 문의하기
Mobile nav
SUPPORT
  • 다운로드 & FAQ
  • 기술적 지원
  • 워런티&RMA 서비스
  • 구매처 정보
  • Certification
    • Barco
    • Chromebook
    • Zoom
  • Security Vulnerability Management

Security Vulnerability Management Policy

1. Purpose

AVerMedia Technologies, Inc. (the "Company") considers product cybersecurity a priority and is committed to establishing a robust, traceable, and effective mechanism for reporting and handling product cybersecurity vulnerabilities. This Policy has therefore been developed with reference to the European Union Cyber Resilience Act (CRA), ISO/IEC 29147 (Vulnerability Disclosure), and other applicable laws, regulations, and standards.

 

The Company welcomes customers, users, security researchers, partners, and other stakeholders to report, in good faith and in a responsible manner, any vulnerability that may affect the cybersecurity of the Company's products. The Company will handle such reports in accordance with its established product cybersecurity vulnerability management process, including intake, technical verification, risk assessment, remediation or mitigation, disclosure, and continuous improvement, with the aim of reducing product cybersecurity risks and protecting users' interests.

 

2. Scope

This Policy primarily applies to Company products that have been placed on the market and remain within their support period, as well as the reporting and handling of cybersecurity vulnerabilities relating to such products. The scope includes:

  1. Hardware, firmware, software, drivers, mobile applications, cloud services, and related supporting systems designed, developed, manufactured, sold, updated, maintained, or technically supported by the Company.

  2. Vulnerabilities identified through external reports, internal testing, public vulnerability databases, supplier security advisories, third-party component information, or other sources, where such vulnerabilities may affect the cybersecurity of the Company's products.

  3. Activities relating to vulnerability intake, acknowledgement, analysis, reproduction, impact assessment, risk classification, remediation, testing, release, disclosure, regulatory reporting, tracking, and closure.

  4. All departments involved in the product lifecycle and product cybersecurity vulnerability management, including the Product Security Incident Response Team (PSIRT), Product Planning, Research and Development, Quality Assurance and Validation, Customer Support, Information Technology, Legal and Regulatory Compliance, and other relevant departments

 

Products that have reached end of support are generally outside the primary scope of this Policy. However, where a report may also affect products or services that remain supported, the Company may conduct the investigations and assessments it considers necessary on a case-by-case basis.

 

3. Vulnerability Handling Principles

Upon receiving a vulnerability report or identifying a potential vulnerability from another source, the Company will handle the matter in accordance with its product cybersecurity vulnerability management process. Handling activities may include:

  1. Acknowledging receipt of the report and creating a case record.

  2. Conducting an initial review, technical verification, and reproduction testing where necessary.

  3. Analyzing the root cause, attack path, affected components, products, versions, and use scenarios.

  4. Assessing the severity of the vulnerability, the likelihood of actual exploitation, and the potential impact.

  5. Determining the remediation or risk mitigation measures and their priority.

  6. Developing, testing, and validating patches, updates, or other risk mitigation measures.

  7. Issuing product security advisories, security updates, or user guidance as necessary.

  8. Completing follow-up tracking, record retention, lessons learned, and continuous improvement.

 

Vulnerability handling priorities will be determined using a risk-based approach. The Company may consider factors including the Common Vulnerability Scoring System (CVSS) score, the likelihood of actual exploitation, the deployment scale and exposure of affected products, the availability of compensating controls, operational or safety impacts, regulatory requirements, and the feasibility of remediation measures.

 

Where a vulnerability involves a third-party component, the Company may coordinate with the supplier, maintainer, or other relevant party responsible for that component to obtain remediation guidance, updates, or other necessary support.

 

4. Company Response

The Company will take appropriate response measures based on the content of the report, the nature of the vulnerability, and the status of the case. Such measures may include acknowledging receipt, requesting additional information, communicating preliminary assessment results, providing case status updates, or informing the reporter of remediation or risk mitigation measures at an appropriate time.

 

Because vulnerabilities vary in complexity, scope of impact, dependencies on third-party components, product lifecycle stage, and remediation validation requirements, actual handling times may differ from case to case. The Company does not guarantee that every vulnerability will be remediated or publicly disclosed within a fixed period.

 

To protect product security, users, confidential business information, or the integrity of the investigation, the Company may be unable to provide complete internal analyses, technical details, or remediation plans. Nevertheless, the Company will maintain communication with the reporter to a reasonable and appropriate extent.

 

5. Target Response Timeframes

To establish an effective and transparent vulnerability reporting mechanism, the Company will use the following timeframes as handling targets, taking into account the nature and severity of the case and the information available. These timeframes are general targets only and do not constitute guaranteed remediation deadlines or a service level agreement:

Handling Stage

Target Timeframe

Acknowledgement and Case ID

Generally within 3 business days after receipt of a complete report.

Initial Review

Confirm within a reasonable period whether the report relates to a Company product and request additional information as necessary.

Technical Verification and Risk Assessment

Based on vulnerability complexity, reproduction requirements, affected products, and the completeness of available information.

Development and Validation of Remediation or Mitigation Measures

Based on vulnerability severity, technical feasibility, third-party component dependencies, and product impact.

Case Status Updates

 

Provided to the reporter as appropriate when material progress has been made, additional information is required, or a suitable handling result is available.

Product Security Advisory

Published as appropriate after a remediation or suitable risk mitigation measure becomes available, taking into account actual risk and disclosure needs.

Actual handling time may be adjusted due to the completeness of the report, vulnerability complexity, reproduction and testing requirements, the product lifecycle, the remediation status of third-party components, regulatory requirements, or other reasonable factors. The Company will prioritize cases based on risk, including cases involving active exploitation, potentially significant impact, or matters requiring immediate action by law.

 

6. Out-of-Scope Matters

The following matters are generally outside the scope of product cybersecurity vulnerabilities accepted under this Policy or do not constitute good-faith research supported by this Policy:

  • Vulnerabilities unrelated to the Company's products or services.
  • General product defects, compatibility issues, feature suggestions, customer service requests, or technical support requests that do not involve cybersecurity risk.
  • The same vulnerability that has already been publicly disclosed and for which the Company has provided a patch, update, or risk mitigation measure, unless the report shows that the existing measure is ineffective.
  • Reports consisting solely of automated scan results, lacking verifiable information, and for which the reporter fails to provide the necessary information after being requested to do so by the Company.
  • An isolated issue affecting only an end-of-support product and assessed as not affecting products or services that remain supported.
  • Social engineering, phishing, physical intrusion, or testing directed at employees, suppliers, customers, or other third parties.
  • Denial-of-service or distributed denial-of-service attacks, traffic stress testing, spam, high-volume automated requests, or other activities that may affect normal operations.
  • Distribution of malware, extortion, data theft, unauthorized access, privilege escalation, establishment of persistence, alteration, deletion, or public disclosure of data, or other unlawful or malicious conduct.

 

If this Policy is updated, the latest version published on the Company's official website shall prevail.

Report Security Vulnerability
  • 회사 소개
    • AVerMedia 소개
    • 연락처
    • 投資人關係
    • 기업의 사회적 책임
  • 미디어
    • 언론
    • 미디어 리뷰 기사
    • 크리에이터 리뷰 영상
    • 공식 제품 영상
    • 제품 튜토리얼 영상
    • 수상 내역
  • 고객지원
    • 다운로드 & FAQ
    • 기술적 지원
    • 보증 & RMA 서비스
    • 구매처 정보
    • EOL
  • 기타
    • Blog
    • 워크 스페이스
    • Store
    • Store
    • 비즈니스 문의
    • 에버미디어 맴버십
    • AVerMedia 파트너 포털
    • 전략적 파트너
    • TAA Compliance
    • NDAA Compliance
    • 개인정보 처리방침
    • AVerMedia AI 고객 서비스 이용약관
    • 웹 사이트 이용 약관
    • MEET ELENA
    • Cookie Settings
fb
linkedin
twitter
youtube
reddit
Language
Copyright © AVerMedia.
  • 제품
    • 웹캠
      • 4K UHD
      • 1080 FULL HD
      • 키트
    • 캡쳐
      • 4K 캡쳐
      • 1080p60 캡쳐
      • AV / S Video 캡쳐
      • DSLR/ CAM모드 캡쳐
      • Video Converter
    • 오디오
      • 스피커폰
      • Soundbars
      • 마이크
      • 무선 마이크
      • 액세서리
    • 방송 컨트롤러
      • Creator Central
    • Video Bar
      • Mingle Bar
    • 스트리밍 확장 스테이션
      • 비디오 제품
      • 오디오 제품
    • 소프트웨어
      • 스트리밍 소프트웨어
  • 워크 스페이스
    • 워크 스페이스
      • 이달의 제품
      • 게임 스트리머
      • 비디오 콘텐츠 창작자
      • 재택근무
      • 교육용
      • 활용 가이드
      • 기업용
  • 고객지원
    • 고객지원
      • 다운로드&FAQ
      • 기술적 지원
      • 워런티&RMA 서비스
      • 구매처
      • 인증
  • 구매처
  • Store
  • 통합 AI 시스템
  • AVerMedia 소개
    • AVerMedia 소개
      • AVerMedia 소개
      • 연락처
      • 投資人關係
      • 기업의 사회적 책임
      • Recruiting
Language