U.S. Department of Energy | Synack

U.S. Department of Energy Responsible Disclosure

Protect U.S. Department of Energy by reporting security vulnerabilities through our Vulnerability Disclosure Program (VDP). Submit findings securely and support a transparent, proactive security process.

Overview

The Department of Energy (DOE) is committed to ensuring the security of the American public by protecting their information from unwarranted disclosure. As such, the DOE has created a Vulnerability Disclosure Program and Policy to give security researchers clear guidelines for conducting vulnerability discovery activities on DOE systems and websites and to convey the DOE’s preferences in how to submit discovered vulnerabilities to the Department.

The Department’s program, and the rules of engagement described herein, describe what systems and types of research are covered under this program, how to submit vulnerability reports, and asks that reporters refrain from publicly disclosing submitted vulnerabilities.

Vulnerability disclosure is the “act of initially providing vulnerability information to a party that was not believed to be previously aware.” The individual or organization that performs this act is called the Reporter. This program allows Reporters to alert the DOE to security flaws they find within the DOE’s public-facing websites. Feedback received through this program allows the DOE to fix flaws quickly when possible, thereby strengthening the integrity of the Department’s information technology systems and enhancing protection of government-owned data.

See DOE Vulnerability Disclosure Policy.

Guidelines

In submitting a request, you agree to:

The DOE appreciates your effort to help strengthen our cyber posture. As part of your good faith testing or research efforts, the Department requests that Reporters:

Scope

All internet-accessible, public facing, systems or services of the U.S. Department of Energy are covered within the scope of the VDP.

Rules of Engagement

Typical Vulnerabilities Accepted:

Typical Out of Scope:

Out of Scope – Low Impact Vulnerabilities

For a full list of program scope please visit the Responsible Disclosure details page.

Contact Information

Company Name: U.S. Department of Energy
Website: https://www.energy.gov/
Submit a Vuln: Start Here
By submitting a vulnerability to our responsible disclosure program, you agree to the Terms of Use.