U.S. Department of Energy | Synack
U.S. Department of Energy Responsible Disclosure
Protect U.S. Department of Energy by reporting security vulnerabilities through our Vulnerability Disclosure Program (VDP). Submit findings securely and support a transparent, proactive security process.
Overview
The Department of Energy (DOE) is committed to ensuring the security of the American public by protecting their information from unwarranted disclosure. As such, the DOE has created a Vulnerability Disclosure Program and Policy to give security researchers clear guidelines for conducting vulnerability discovery activities on DOE systems and websites and to convey the DOE’s preferences in how to submit discovered vulnerabilities to the Department.
The Department’s program, and the rules of engagement described herein, describe what systems and types of research are covered under this program, how to submit vulnerability reports, and asks that reporters refrain from publicly disclosing submitted vulnerabilities.
Vulnerability disclosure is the “act of initially providing vulnerability information to a party that was not believed to be previously aware.” The individual or organization that performs this act is called the Reporter. This program allows Reporters to alert the DOE to security flaws they find within the DOE’s public-facing websites. Feedback received through this program allows the DOE to fix flaws quickly when possible, thereby strengthening the integrity of the Department’s information technology systems and enhancing protection of government-owned data.
See DOE Vulnerability Disclosure Policy.
Guidelines
In submitting a request, you agree to:
- Accept and adhere to the Terms of Use.
- Work directly with Synack on vulnerability submissions.
- Provide detailed description of a proof of concept to detail reproduction of vulnerabilities.
- Adhere to these Guidelines and the Rules of Engagement and Scope, and do not engage in disruptive testing like DoS or any action that could impact the confidentiality, integrity or availability of information and systems.
- Do not engage in social engineering or phishing of customers or employees.
- Do not request compensation for time and materials or vulnerabilities discovered.
The DOE appreciates your effort to help strengthen our cyber posture. As part of your good faith testing or research efforts, the Department requests that Reporters:
- Notify the Department as soon as possible after you discover a real or potential security issue using the process outlined herein;
- Provide us with a reasonable amount of time to resolve the issue before you disclose it publicly or to additional parties;
- Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data;
- Only use exploits to the extent necessary to confirm a vulnerability’s presence. Do not use an exploit to compromise or exfiltrate data, establish command line access and/or persistence, or use the exploit to “pivot” to other systems;
- Cease and desist all testing activities if you establish that a vulnerability exists or encounter any sensitive data (e.g., including personally identifiable information, financial information, or proprietary information or trade secrets of any party), notify the DOE immediately, and not disclose this data to anyone else. Sensitive information identified may be covered under other Federal or legal requirements, regulations, or safeguarding measures that supercede the protections and authority of the Department’s Vulnerability Disclosure Program and these rules of engagement; and
- Avoid submittal of a high volume of low-quality reports by using the Common Vulnerability Scoring System (CVSS) or other similar methodology to assess the significance of a vulnerability prior to submitting it.
Scope
All internet-accessible, public facing, systems or services of the U.S. Department of Energy are covered within the scope of the VDP.
Rules of Engagement
- No Denial of Service testing
- No Physical or Social Engineering
- No testing of Third-party Services
- No uploading of any vulnerability or client-related content to third-party utilities (e.g. Github, DropBox, YouTube)
- All attack payload data must use professional language
- If able to gain access to a system, accounts, users, or user data, stop at point of recognition and report. Do not dive deeper to determine how much more is accessible.
Typical Vulnerabilities Accepted:
- OWASP Top 10 vulnerability categories
- Other vulnerabilities with demonstrated impact
Typical Out of Scope:
- Theoretical vulnerabilities
- Informational disclosure of non-sensitive data
- Low impact session management issues
- Self XSS (user defined payload)
Out of Scope – Low Impact Vulnerabilities
- Google Maps API Keys
- Account/e-mail enumeration using brute-force attacks
- Valid user account/email enumeration not requiring brute-force will be considered
- Any low impact issues related to session management (i.e. concurrent sessions, session expiration, password reset/change log out, etc.)
- Bypassing content restrictions in uploading a file without proving the file was received
- Clickjacking/UI redressing
- Client-side application/browser autocomplete or saved password/credentials
- Descriptive or verbose error pages without proof of exploitability or obtaining sensitive information
- And more...
For a full list of program scope please visit the Responsible Disclosure details page.
Contact Information
Company Name: U.S. Department of Energy
Website: https://www.energy.gov/
Submit a Vuln: Start Here
By submitting a vulnerability to our responsible disclosure program, you agree to the Terms of Use.