generated: '2026-09-06' method: searched probe: true source: https://www.enersys.com/en/about-us/quality/cve-disclosures/ provider: EnerSys providerId: enersys description: >- EnerSys operates a public product-security disclosure surface: a "Common Vulnerabilities and Exposures (CVE) Disclosures" page under About Us > Quality that publishes advisories for vulnerabilities affecting EnerSys products, each linked to a PDF advisory. The page states the company follows responsible disclosure practices, but it publishes NO intake channel — no security@ address, no PSIRT contact, no reporting form, and no /.well-known/security.txt on any EnerSys host. This is a disclosure OUTPUT surface without a documented disclosure INPUT path. policy: published: true url: https://www.enersys.com/en/about-us/quality/cve-disclosures/ statement: >- "We follow responsible disclosure practices and collaborate with security researchers and third-party experts to ensure vulnerabilities are addressed swiftly and effectively." scope: EnerSys products (advisories name affected product models) contact: published: false note: >- No reporting email, PSIRT alias, form or bug-bounty program is published on the CVE disclosures page or anywhere else found on enersys.com. The only routing offered is the general "Contact Us" form. fallback: https://www.enersys.com/en/contact-us/ security_txt: served: false note: /.well-known/security.txt returns 404 on enersys.com, www.enersys.com, bsp.enersys.com, mptools.enersys.com and xinx.enersys.com. bug_bounty: program: none note: No HackerOne, Bugcrowd or Intigriti program found for EnerSys. advisories: - cve: CVE-2024-11861 title: Web Interface Vulnerability affected_products: - XM3.1-HP 910-918 - XM3.1-HP 903-905 - SMG-HP - ADOM posted: '2025-05-09' advisory: https://www.enersys.com/4996bf/globalassets/documents/corporate/cve/enersys_cve-2024-11861-final.pdf - cve: CVE-2024-12442 title: Single Webpage (Network Diagnostics) RCE Vulnerability affected_products: - XM3.1-HP 910-918 - XM3.1-HP 903-905 - SMG-HP - ADOM posted: '2025-05-09' advisory: https://www.enersys.com/4996df/globalassets/documents/corporate/cve/enersys_cve-2024-12442-final.pdf evidence: - source: https://www.enersys.com/en/about-us/quality/cve-disclosures/ kind: product security disclosure page (live fetch) http_status: 200 fetched: '2026-09-06' keywords: - responsible disclosure - cybersecurity vulnerabilities - CVE gaps: - No published vulnerability-reporting contact or intake channel. - No /.well-known/security.txt (RFC 9116) on any EnerSys host. - No stated coordinated-disclosure timeline or safe-harbor language.