generated: '2026-08-23' method: searched source: https://www.inspur.com/lcjtww/2312126/2432763/index.html note: 'Inspur Cloud does not run its own vulnerability disclosure programme. The programme belongs to Inspur Group''s PSIRT (Product Security Incident Response Team) on inspur.com, the parent company whose domain Inspur Cloud''s corporate site also sits under, and it covers "Inspur products" generally rather than the cloud platform specifically. Recorded here as the disclosure route a researcher would actually use, with that scope caveat stated. There is no /.well-known/security.txt on any Inspur host.' program: exists: true operator: Inspur Group PSIRT scope: Inspur products (not scoped explicitly to the Inspur Cloud platform) url: https://www.inspur.com/lcjtww/2312126/2432763/index.html advisories_url: https://www.inspur.com/lcjtww/psirt/security-advisories/index.html probed: - url: https://www.inspur.com/lcjtww/2312126/2432763/index.html status: 200 - url: https://www.inspur.com/lcjtww/psirt/security-advisories/index.html status: 200 contact: email: sec@inspur.com encryption: PGP key_id: '0xC483FD05' fingerprint: 9C0A 9271 6CF9 0CF6 8B28 0606 7CF5 0934 C483 FD05 submission_requirements: - Reporter or organisation name and contact details - Affected products and versions - How the vulnerability was found, with detailed reproduction steps - Proof of exploitation / PoC - Suggested remediation bug_bounty: exists: false detail: No monetary reward, HackerOne, Bugcrowd or Intigriti programme is referenced. disclosure_policy: published: partial detail: 'A vulnerability response process document is linked from the reporting page, but no embargo period, acknowledgement SLA, or coordinated-disclosure timeline is stated on the public page.' security_txt: served: false detail: /.well-known/security.txt returns 404 on cloud.inspur.com, console1.cloud.inspur.com and en.inspur.com (probed 2026-08-23). advisory_track_record: publishes_advisories: true examples: - CVE-2024-1086 Linux kernel netfilter use-after-free privilege escalation - CVE-2021-30465 runc symlink-swap container escape - CVE-2020-11651 SaltStack unauthenticated remote command execution - Apache Log4j2 remote code execution - sudo privilege escalation note: 'The advisories are downstream OS/component notices for Inspur hardware and software products. No advisory specific to an Inspur Cloud API or platform service was found.'