generated: '2026-07-25' method: searched probe: true source: https://www.etsi.org/standards/coordinated-vulnerability-disclosure/ program: ETSI Coordinated Vulnerability Disclosure (CVD) policy: - https://www.etsi.org/standards/coordinated-vulnerability-disclosure/ contact: - ETSI_CVD@etsi.org submission: online form on the Coordinated Vulnerability Disclosure page scope: >- Vulnerabilities caused by errors, omissions or ambiguities in ETSI standards — that is, flaws in the specification itself, not in a vendor's implementation of it. ETSI states explicitly that it is responsible for writing and issuing Technical Specifications and is not responsible for proprietary equipment designed, built and tested to those specifications. process: - ETSI acknowledges every declaration received - the report is routed to the ETSI Technical Group best placed to analyse and resolve it - the reporter is notified when the vulnerability has been eliminated - reports may be submitted anonymously; ETSI guarantees not to attempt to identify anonymous reporters - non-anonymous reporters may opt to be publicly credited in ETSI's hall of fame embargo: >- ETSI asks reporters not to share knowledge of the vulnerability with third parties until ETSI has resolved it, and not to exploit it beyond what is necessary to gather enough data to report it bounty: offered: false note: ETSI is a not-for-profit association; CVD disclosures generate no financial compensation hall_of_fame: true security_txt: published: false note: no RFC 9116 /.well-known/security.txt on any ETSI host — see well-known/etsi-well-known.yml related_standards: - id: etsi-tr-103-838 title: 'ETSI TR 103 838: Guide to Coordinated Vulnerability Disclosure' url: https://www.etsi.org/deliver/etsi_tr/103800_103899/103838/01.01.01_60/tr_103838v010101p.pdf - id: etsi-en-303-645 title: 'ETSI EN 303 645: Cyber Security for Consumer Internet of Things — mandates a vulnerability disclosure policy as provision 5.2-1' url: https://www.etsi.org/technologies/consumer-iot-security evidence: - source: https://www.etsi.org/standards/coordinated-vulnerability-disclosure/ kind: disclosure-policy-page status: 200 - source: https://www.etsi.org/newsroom/press-releases/2029-2022-02-etsi-releases-report-on-coordinated-vulnerability-disclosure kind: press-release note: >- The mechanical probe in 0-working/probe-security-programs.py reports vdp=none for etsi.org because www.etsi.org answers a bare curl with HTTP 403; the program is real and was confirmed with a browser user agent.