generated: '2026-09-05' method: searched source: https://www.carrier.com/us/en/product-security/report-an-issue.html provider: Carrier Global providerId: carrier-global program: name: Carrier Product Security Incident Response Team (PSIRT) published: true url: https://www.carrier.com/us/en/product-security/report-an-issue.html http_status: 200 policy_url: https://www.carrier.com/us/en/product-security/report-an-issue.html advisories_url: https://www.carrier.com/us/en/product-security/advisories.html program_overview_url: https://www.carrier.com/us/en/product-security.html bug_bounty: false bounty_platform: none evidence: - url: https://hackerone.com/carrier status: 404 - url: https://bugcrowd.com/carrier status: 404 scope: >- "Carrier encourages reporters, including security researchers, end-users, and vendors, to contact us with any information relating to potential security flaws or vulnerabilities within any of our offerings." The advisories index covers Automated Logic WebCTRL, Carrier i-Vu, Carrier and Automated Logic zone controllers, Viessmann Vitogate 300 and Carrier-wide responses to third-party CVEs (MOVEit, Log4j, Spring4Shell, Text4Shell, OpenSSL 3.0, Apache Shiro, Okta/Lapsus$). disclosure_model: coordinated disclosure_statement: >- "The Carrier Product Security Incident Response Team (PSIRT) employs a coordinated approach to vulnerability disclosure and publication. PSIRT determines the best path when issuing security advisories for our supported Carrier [offerings]." mission_statement: >- "Carrier endeavors to ensure that validation, analysis, and mitigation of findings are proactively communicated in a responsible manner. The Carrier PSIRT Plan prepares and discloses product security advisory publications to acknowledge the reporters, vulnerabilities, impacts, and mitigations of the reported incidents." acknowledgement_sla: Receipt of issue/concern notification will be provided within 48 hours. reporter_credit: >- Advisories are stated to acknowledge the reporters, so researcher credit is part of the published process. cna: true cna_evidence: >- Carrier states it serves as a "CVE Numbering Authority (CNA)" on https://www.carrier.com/us/en/product-security.html, and its advisories carry CVE identifiers it has assigned (e.g. CVE-2024-8525/8526/8527/8528, CVE-2025-9494/9495, CVE-2026-24060/25086/32666). reporting: channels: - kind: web-form url: https://www.carrier.com/us/en/product-security/report-an-issue.html fields_requested: - Software / Firmware / Hardware version - Description of issue / concern (required) - Reproduction steps (required) - kind: encrypted-email preferred: true note: >- "Preferred Secure Reporting Method: Encrypted Content (PGP). For sensitive vulnerability details, please encrypt your message using OpenPGP (PGP) before sending email." Carrier publishes both full instructions and the public key for download from the same page. pgp: published: true fingerprint: 8744 2AB6 27A4 EAB6 A82F 798D 5ED7 A15E 6180 7FB6 note: >- Fingerprint transcribed verbatim from the published page. The key itself is offered as a download link on that page and is not mirrored here. postal_address: 13995 Pasteur Blvd. Palm Beach Gardens, FL 33418 security_txt: published: false note: >- Carrier runs a full PSIRT with a published PGP key and a coordinated disclosure policy but does NOT publish /.well-known/security.txt on any of its hosts — the single cheapest thing it could do to make this program machine-discoverable. See well-known/carrier-global-well-known.yml for the probe record. alliances: - Founding Member of the ISA Global Cybersecurity Alliance maintainers: - FN: Kin Lane email: info@apievangelist.com