Coordinated Disclosure
Coordinated Disclosure Policy
Universal Robots encourages customers, security researchers, and other interested parties to responsibly disclose discovered security vulnerabilities or safety concerns in collaboration with us.
Please use the vulnerability and incident reporting platform at https://www.teradyne.com/product-security/ . This central intake system will guide you through submitting your report for triage and analysis. Alternatively, and in case you may have other inquiries, you can reach out to Teradyne Robotics product security team directly by email at productsecurity@teradyne-robotics.com. Non-critical submissions will typically be processed within five business days.
Teradyne Robotics is a Certified Numbering Authority (CAN) under CISA ICS and we are committed to transparency by sharing and reporting CVEs through cve.org. More information can be found here: https://www.cve.org/PartnerInformation/ListofPartners/partner/TRO.
Please note that Universal Robots does not offer rewards for disclosed vulnerabilities. However, we do provide full attribution to the parties who discovered the vulnerability, if so desired.
We are committed to the safety and security of our users worldwide. Universal Robots reserves the right to withhold disclosure of a received cybersecurity vulnerability if we believe it would expose our users to excessive risk. In such cases, we will work with the reporting party to establish a timeline for disclosure that will be beneficial to our customers and the general public.
When performing security assessments, always adhere to applicable local laws and regulations and consider the safety, security, and privacy of affected individuals at all times. Only perform security assessments on systems that you either own or have permission to assess. Do not perform security assessments on systems owned by Universal Robots without prior express written consent from Universal Robots.