Dematic | Synack
Dematic Vulnerability Disclosure
Protect Dematic by reporting security vulnerabilities through our Vulnerability Disclosure Program (VDP). Submit findings securely and support a transparent, proactive security process.
* By submitting a vulnerability, you agree to the Terms of Use.
Overview
This Responsible Disclosure Program (the “Program”) page is for security researchers interested in reporting application security vulnerabilities. This is intended for application security vulnerabilities only.
Vulnerabilities submitted to the Program through the form provided will be reviewed by Synack, Inc. (“Synack”). Submissions will be reviewed to confirm they are within the Program scope and a valid security issue. If you submit a valid vulnerability, you will be notified after a fix has been issued, and you will have the opportunity to be added to the Acknowledgments page and to disclose the vulnerability. The submission review and validation process is managed exclusively by Synack through their platform and you must follow the Guidelines, Rules of Engagement, and Scope set forth below to participate. All submissions and queries regarding the Program should be submitted through the Submission Form.
Guidelines
In submitting a request, you agree to:
- Accept and adhere to the Terms of Use.
- Work directly with Synack on vulnerability submissions.
- Provide detailed description of a proof of concept to detail reproduction of vulnerabilities.
- Adhere to these Guidelines and the Rules of Engagement and Scope, and do not engage in disruptive testing like DoS or any action that could impact the confidentiality, integrity or availability of information and systems.
- Do not engage in social engineering or phishing of customers or employees.
- Do not request compensation for time and materials or vulnerabilities discovered.
The following web applications are in scope: *.dematic.com
Rules of Engagement
- No Denial of Service testing
- No Physical or Social Engineering
- No testing of Third-party Services
- No uploading of any vulnerability or client-related content to third-party utilities (e.g. Github, DropBox, YouTube)
- All attack payload data must use professional language
- If able to gain access to a system, accounts, users, or user data, stop at point of recognition and report. Do not dive deeper to determine how much more is accessible.
Out of Scope – Low Impact Vulnerabilities
The following vulnerabilities are considered too low of an impact to the client and would be marked as Out of Scope if submitted:
- Google Maps API Keys
- Account/e-mail enumeration using brute-force attacks
- Valid user account/email enumeration not requiring brute-force will be considered
- Any low impact issues related to session management (i.e. concurrent sessions, session expiration, password reset/change log out, etc.)
- Bypassing content restrictions in uploading a file without proving the file was received
- Clickjacking/UI redressing
- Client-side application/browser autocomplete or saved password/credentials
- Descriptive or verbose error pages without proof of exploitability or obtaining sensitive information
- Directory structure enumeration (unless the fact reveals exceptionally useful information)
- Incomplete or missing SPF/DMARC/DKIM records
- Issues related to password/credential strength, length, lockouts, or lack of brute-force/rate-limiting protections
- Account compromises (especially admin) as a result of these issues will likely be considered VALID
- Lack of SSL or Mixed content
- Leaking Session Cookies, User Credentials, or other sensitive data will be reviewed on a case by case basis
- If leaking of sensitive data requires MiTM positioning to exploit, it will be considered out of scope
- Login/Logout/Unauthenticated/Low-impact CSRF
- CSRF Vulnerabilities may be acceptable if they are of higher impact. Examples of low impact CSRF include: Add/Delete from Cart, Add/remove wishlist/favorites, Nonsevere preference options, etc.
- Low impact Information disclosures (including Software version disclosure)
- Missing Cookie flags
- Missing/Enabled HTTP Headers/Methods which do not lead directly to a security vulnerability
- Reflected file download attacks (RFD)
- Self-exploitation (i.e. password reset links or cookie reuse)
- SSL/TLS best practices that do not contain a fully functional proof of concept
- URL/Open Redirection
- Use of a known-vulnerable library which leads to a low-impact vulnerability (i.e. jQuery outdated version leads to low impact XSS)
- Valid bugs or best practice issues that are not directly related to the security posture of the client
- Vulnerabilities affecting users of outdated browsers, plugins or platforms
- Vulnerabilities that allow for the injection of arbitrary text without allowing for hyperlinks, HTML, or JavaScript code to be injected
- Vulnerabilities that require the user/victim to perform extremely unlikely actions (i.e. Self-XSS)
- Self-XSS for a Persistent/Stored XSS will be considered. Please review the Self-XSS article for more information.
- Any type of XSS that requires a victim to press an unlikely key combination is NOT in scope (i.e. alt+shift+x for payload execution)
Additional specific vulnerability types considered out of scope due to low impact:
- IIS Tilde File and Directory Disclosure
- SSH Username Enumeration
- WordPress Username Enumeration
- SSL Weak Ciphers/ POODLE / Heartbleed
- CSV Injection
- PHP Info
- Server-Status if it does not reveal sensitive information
- Snoop Info Disclosures
I. Overview
The following terms of use (the “Terms of Use”) apply when you view or use a Responsible Disclosure Program hosted by Synack, Inc. (“Synack”, “we”, “our”, “us”) on Synack’s websites. By using our Site, you agree to fully comply with and be bound by the Terms of Use. Please review them carefully. If you do not accept our Terms of Use, do not access and use our Site. If you have already accessed our Site and do not accept our Terms of Use, you should immediately discontinue use of our Site. Synack commits that, if we conclude, in our sole discretion, that a security vulnerability submitted through our Site complies with the Terms of Use, the applicable Scope and Rules of Engagement and the applicable Responsible Disclosure Guidelines, Synack will not bring a private action against you or refer the matter for public inquiry.
II. Privacy Policy
We respect the privacy of our Site visitors. Please refer to our Privacy Policy which explains how we collect, use, and disclose information that pertains to your privacy. When you access or use our Site, you signify your agreement to this Privacy Policy.
III. Eligibility Requirements
You agree that you will not under any circumstances:
- Cause harm to us, our customers or others;
- Be a resident of, or make your Submission from, a country or region against which the United States has issued export sanctions or other trade restrictions (e.g., Cuba, Iran, North Korea, Syria, Russia, and Crimea);
- Be listed on the U.S. Department of the Treasury’s Specially Designated Nationals List;
- Be in violation of any national, state, or local law or regulation;
- Compromise our privacy or safety or the privacy or safety of our customers (including their customers) and our operation or the operation of our customers’ services;
- Store, share, compromise or destroy our or our customers’ data; or
- Be less than 14 years of age. If you are at least 14 years old, but are considered a minor in your place of residence, you must get your parent’s or legal guardian’s permission prior to participating in the program.
If we discover that you do not meet any of the criteria above, we will remove you from the applicable Responsible Disclosure Program. Any submissions you make to the Responsible Disclosure Program, whether via the submission form or via email shall be considered “Submission(s)” for purposes of these Terms of Use.
IV. Posting and Conduct Restrictions
By transmitting any Submission while using our Site, you agree, represent and warrant as follows:
- If you create an account to view the status of your submission, you are solely responsible for your account and the activity that occurs while signed in to or while using your account.
- You will not transmit content that is copyrighted or subject to third party proprietary rights, including privacy, publicity, trade secret, etc., unless you are the owner of such rights or have the appropriate permission from their rightful owner to specifically submit such content to us.
- You hereby affirm we have the right to determine whether any of your Submissions are appropriate and comply with these Terms of Use, remove any and/or all of your communications, and terminate your account with or without prior notice.
- You will not send unsolicited bulk communications, interfere or attempt to interfere with the proper functioning of our or our customers’ websites and systems, and will not publish or link to malicious content intended to damage or disrupt another user’s browser or computer.
- You will not take any action that we deem to impose or to potentially impose an unreasonable or disproportionately large load on our or our customers’ servers or network infrastructure.
V. Access Limitation; Appropriate Action
We reserve the right, but are not obligated, to limit or deny access to our Site and to take other appropriate action if a user violates these Terms of Use or engages in any activity that violates the rights of any person or entity or which we deem unlawful, offensive, abusive, harmful or malicious.
VI. License Grant
By transmitting your submission to a Responsible Disclosure Program, you perpetually allow us and our affiliates the unconditional ability to use, modify, create derivative work from, distribute, disclose and store the information provided in your Submission or to have others do the same on our behalf, and these rights cannot be revoked. You represent that the Submission is original to you and that you own all right, title and interest in the submission.
VII. Intellectual Property
You acknowledge and agree that we retain ownership of all intellectual property rights of any kind related to our Site, including applicable copyrights, trademarks and other proprietary rights. Other product and company names that are mentioned on our Site may be trademarks of their respective owners. We reserve all rights that are not expressly granted to you in the Terms of Use.
VIII. Disclaimer; Limitation of Damages; Release
OUR SITE IS PROVIDED “AS IS” WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING ANY WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, SECURITY, ACCURACY AND NON-INFRINGEMENT. WITHOUT LIMITING THE FOREGOING, WE MAKE NO WARRANTY OR REPRESENTATION THAT ACCESS TO OR OPERATION OF THE SITE WILL BE UNINTERRUPTED OR ERROR FREE. YOU ASSUME FULL RESPONSIBILITY AND RISK OF LOSS RESULTING FROM YOUR DOWNLOADING AND/OR USE OF FILES, INFORMATION, CONTENT OR OTHER MATERIAL OBTAINED FROM THE SITE. TO THE EXTENT PERMITTED BY LAW, IN NO EVENT SHALL WE, OUR AFFILIATES, OFFICERS, DIRECTORS, EMPLOYEES, AGENTS, REPRESENTATIVES OR OUR CUSTOMERS BE LIABLE FOR ANY DIRECT, INDIRECT, PUNITIVE, INCIDENTAL, SPECIAL, CONSEQUENTIAL OR EXEMPLARY DAMAGES, INCLUDING WITHOUT LIMITATION DAMAGES FOR LOSS OF PROFITS, GOODWILL, USE, DATA OR OTHER INTANGIBLE LOSSES, THAT RESULT FROM (A) THE USE, DISCLOSURE, OR DISPLAY OF YOUR INFORMATION OR CONTENT; (B) YOUR USE OR INABILITY TO USE THE SITE; (C) THE SITE GENERALLY OR THE SOFTWARE OR SYSTEMS THAT MAKE THE SITE AVAILABLE; OR (D) ANY OTHER INTERACTIONS WITH THE SITE OR ANY OTHER USER OF THE SITE, WHETHER BASED ON WARRANTY, CONTRACT, TORT (INCLUDING NEGLIGENCE) OR ANY OTHER LEGAL THEORY, WHETHER OR NOT WE HAVE BEEN INFORMED OF THE POSSIBILITY OF SUCH DAMAGE, AND EVEN IF A REMEDY SET FORTH HEREIN IS FOUND TO HAVE FAILED OF ITS ESSENTIAL PURPOSE.
IX. Confidentiality
Any information you receive or collect about us or any of our customers through the Responsible Disclosure Program (“Confidential Information”) must be kept confidential and only used in connection with the Responsible Disclosure Program. You may not use, disclose or distribute any such Confidential Information, including, but not limited to, any information regarding your Submission and information you obtain when researching the sites of our customers, without our prior written consent.
X. Indemnity
You agree to defend, indemnify and hold harmless us and our customers and their respective affiliates, officers, directors, employees, agents and representatives, from and against any and all claims, damages, obligations, losses, liabilities, costs or debt, and expenses (including but not limited to reasonable attorney’s fees) arising from: (i) your use of and access to our Site; (ii) your violation of any term of these Terms of Use; (iii) your violation of any third party right, including without limitation any copyright, property, or privacy right; or (iv) any claim that any content submitted by you causes damage to a third party. This defense and indemnification obligation will survive these Terms of Use and your use of the Responsible Disclosure Program and our Site.
XI. Modifications of Terms of Use
We can amend these Terms of Use at any time and will update these Terms of Use in the event of any such amendments. It is your sole responsibility to check our Site from time to time to view any such changes. If you continue to access or use our Site, you signify your agreement to our revisions to these Terms of Use.
XII. Applicable Laws; Venue
These Terms of Use and your use of our Site are governed by the laws of the State of California. Any action related to this Site will be filed exclusively in San Mateo County, California. By using this Site, you signify your consent to the jurisdiction of the state and federal courts located in San Mateo County, California in connection with any controversy arising out of your use of our Site and agree not to bring any action in any other jurisdiction.
XIII. Suggestions and Feedback
We welcome your feedback and inquiries. If you have any comments or questions, please contact us by sending an email to support@synack.com.
Last updated: January 8, 2025
Company Name
Dematic
Website
Submit a Vuln
By submitting a vulnerability to our responsible disclosure program, you agree to the Terms of Use.