Cyber Resilience Act Compliance¶
This section collects the information that Würth IT Italy makes publicly available for NetEye under Regulation (EU) 2024/2847, the Cyber Resilience Act (CRA).
Reporting a CRA Incident¶
Use the address below to notify Würth IT Italy of an event that falls under Article 14 of the Cyber Resilience Act, that is:
a vulnerability in NetEye that is being actively exploited — report an actively exploited vulnerability, or
a severe security incident affecting the security of NetEye — report a severe security incident.
Important
CRA incident contact: security.neteye@wuerth-it.com
Report as soon as you become aware of the situation, without waiting for a complete analysis. Under Article 14 of Regulation (EU) 2024/2847, Würth IT Italy must submit an early warning to the competent CSIRT and to ENISA within 24 hours of becoming aware of an actively exploited vulnerability or a severe incident. Every hour of delay in reaching us reduces the time available to assess the situation and to warn other users.
Please include, as far as it is known to you at the time of reporting:
The NetEye version and build in use, and the affected component or module
What you observed, and what leads you to believe the issue is being exploited
When the activity was first observed, and whether it is ongoing
The impact you have identified so far, and any systems known to be affected
Any indicators of compromise, log excerpts or artefacts you can share
A contact person we can reach for follow-up questions
Do not delay the report in order to complete this information. Send what you have and follow up afterwards.
Note
This address is intended for actively exploited vulnerabilities and severe incidents only. For all other security findings, including vulnerabilities that are not known to be exploited, use the regular channels described in Reporting Vulnerabilities. Reports sent to either address reach the same security team, so a report sent to the wrong address is never lost — it may simply be handled with a different priority.
What happens after you report¶
We acknowledge your report and assess whether it meets the criteria of Article 14.
Where it does, we notify the competent CSIRT and ENISA within the statutory deadlines and keep you informed of the classification we applied.
We inform affected users about the vulnerability or incident, about the corrective measures available and, where applicable, about mitigating measures they can take themselves.
Once a fix is available, we publish a security advisory. Fixes follow the timeframes set out in the Bugfix Policy.
Reporting an incident to us does not replace any reporting obligation you may have yourself, for example under NIS2, DORA or data protection law.