generated: '2026-07-25' method: searched probe: true source: >- https://www.nokia.com/.well-known/security.txt (HTTP 200, PGP-signed) and https://www.nokia.com/we-are-nokia/security/products/cvd/ (HTTP 200). summary: >- The mechanical probe found nothing, because it looked at the product hosts - networkascode.nokia.io serves its SPA 404 for every /.well-known/ path and the RapidAPI gateway answers "API doesn't exists". The programme is at the corporate parent and it is a strong one: a named Coordinated Vulnerability Disclosure programme that explicitly covers "Nokia products and Nokia-hosted services" (which is what Network as Code is), a PGP-signed RFC 9116 security.txt, a published PGP fingerprint, a researcher hall of fame, and CVE Numbering Authority status. program: Nokia Coordinated Vulnerability Disclosure (CVD) Program policy: - https://www.nokia.com/we-are-nokia/security/products/cvd/ contact: - security-alert@nokia.com security_txt: url: https://www.nokia.com/.well-known/security.txt status: 200 file: well-known/nokia-network-as-code-security.txt signed: true expires: '2036-12-31T23:00:00Z' preferred_languages: en encryption: pgp_key: https://www.nokia.com/.well-known/nokia-public-key.asc fingerprint: B88A5B043A75E913D601F23ACBDD1EFF75E14178 acknowledgments: https://www.nokia.com/we-are-nokia/security/products/cvd/hall-of-fame/ advisories: https://www.nokia.com/we-are-nokia/security/product-security-advisory/ cna: true cna_note: Nokia is a CVE Numbering Authority and may assign CVE IDs for confirmed vulnerabilities in actively supported products. bug_bounty: paid: false note: >- No monetary bounty and no HackerOne / Bugcrowd / Intigriti presence was found. Recognition is via the hall of fame. Anonymous submissions are explicitly accepted. scope_note: >- The CVD page states it is intended for security researchers not affiliated with Nokia customers; Nokia customers are directed to their customer team contact instead. Reports that are only automated scanner output or generic CVE notifications without reproduction steps are explicitly out of scope. process: - Acknowledge receipt of the report. - Maintain communication throughout the investigation. - Determine resolution timelines based on severity and complexity. - Assign a CVE ID where the vulnerability affects an actively supported product. evidence: - {source: 'https://www.nokia.com/.well-known/security.txt', kind: security.txt, status: 200} - {source: 'https://www.nokia.com/we-are-nokia/security/products/cvd/', kind: disclosure-policy, status: 200} - {source: well-known/nokia-network-as-code-security.txt, kind: harvested-file} probe_results: - {url: 'https://networkascode.nokia.io/.well-known/security.txt', status: 404} - {url: 'https://developer.networkascode.nokia.io/.well-known/security.txt', status: 404} - {url: 'https://network-as-code.p-eu.rapidapi.com/.well-known/security.txt', status: 404, note: 'Declared as a real operation in the OpenAPI but gated behind the gateway API key.'}