Bonfiglioli Product Security Incident Response Team (PSIRT) 

Report a Product Security Vulnerability or Security Incident 

Bonfiglioli is committed to ensuring the cybersecurity, safety and resilience of its Products with Digital Elements throughout their lifecycle. If you believe you have identified a cybersecurity vulnerability or security incident affecting a Bonfiglioli product, please submit a report using the Product Security Reporting Form available on this page. 
 
The information provided will be reviewed by the Bonfiglioli Product Security Incident Response Team (PSIRT) which, together with the appropriate internal functions, coordinates assessment, investigation, remediation, customer communication and regulatory reporting activities where applicable. 
 
Bonfiglioli supports Coordinated Vulnerability Disclosure (CVD) and encourages responsible reporting from customers, partners, integrators, suppliers and security researchers. 

This process applies to cybersecurity vulnerabilities and security incidents related to Bonfiglioli Products with Digital Elements, including drives, inverters, motion systems, controllers, IoT devices, communication modules, gateways, embedded software, firmware, companion applications and cloud services associated to the products. 

If you are unsure whether your report falls within scope, please submit it and the PSIRT will perform an initial assessment. 

Bonfiglioli welcomes reports from customers, distributors, integrators, supplierspartners and security researchers. 
 
Security Vulnerabilities include authentication weaknesses, privilege escalation, hardcoded credentials, insecure configurations, weak cryptography, insecure update mechanisms, exposed interfaces and any weakness potentially impacting confidentiality, integrity, availability, authenticity or safety-related functions. 
 
Security Incidents shall provide evidence of active exploitation by a malicious adversaryincluding malware execution, unauthorized access, compromise of firmware or software components, supply-chain related compromises and cybersecurity events affecting products already deployed in the field. 

Bonfiglioli supports Coordinated Vulnerability Disclosure and encourages responsible reporting. 
 
We kindly ask reporters to: 
• Avoid public disclosure until Bonfiglioli has had a reasonable opportunity to validate the report and develop appropriate mitigations. 
• Provide sufficient technical details for reproducibility 
• Allow reasonable time for investigation and remediation 
• Cooperate with Bonfiglioli throughout the assessment process 
 
Where appropriate, Bonfiglioli may acknowledge contributors unless anonymity is requested. 

Reports should be submitted through the Bonfiglioli Product Security Reporting Form. 
 
The form is designed to support rapid triage and collects structured information including: 
 
• Reporter identity and contact details 
• Product family 
• Material number and serial number (when available) 
• Type of report (Vulnerability, Security Incident, Suspected Security Issue) 
• Technical description of the issue 
• Evidence of exploitation or malicious activity 
• Potential impact on product operation and safety-related functions 
 Potential impact on Bonfiglioli products different than the one subject of the report  
• Reproducibility information 
• Supporting files such as logs, screenshots, traces or proof-of-concept material 
 
Providing complete information significantly improves assessment speed and response effectiveness. 

If you share any information with Bonfiglioli in the context of responsible disclosure, you agree that the information you submit will be considered non-proprietary. Bonfiglioli is allowed to use shared information, or part of it, without any restriction, including the actions related to regulatory reporting obligations. 

Initial Triage and Classification 

All reports are reviewed by the Bonfiglioli PSIRT. 
 
The PSIRT performs an initial assessment to determine: 
• Information completeness 
• Scope applicability 
• Security relevance  
• Vulnerability versus Incident classification 
• Urgency level 
 
Reports that are not cybersecurity-related may be redirected to the appropriate support channel. 
 
Cybersecurity-relevant reports are assigned to the responsible product team for technical investigation. 

Vulnerability Assessment Process 

For vulnerability reports, the responsible product team performs technical validation activities including reproducibility analysis, exploitability assessment, root cause identification, severity evaluation and safety impact assessment where applicable. 
 

Security Incident Assessment Process 

For security incidents or suspected incidents, the responsible product team performs incident analysis activities to determine whether exploitation has occurred, whether products are affected in the field and whether containment or mitigation actions are required. 

Remediation and Corrective Actions 

Depending on the assessment outcome, Bonfiglioli may implement: 
 
• Security patches 
• Firmware or software updates 
• Configuration recommendations 
• Product documentation updates 
• Security hardening measures 
• Customer notifications 
• Security advisories 
 
Remediation activities are prioritized based on severity, exploitability and customer impact. 

Actively exploited vulnerabilities and severe security incidents. 

Bonfiglioli evaluates confirmed vulnerabilities and security incidents against applicable regulatory obligations, including the EU Cyber Resilience Act (CRA). 
 
Where required, Bonfiglioli may submit notifications and follow-up reports to competent authorities, including reports related to actively exploited vulnerabilities and severe security incidents. 
 
Regulatory reporting activities are coordinated through the appropriate internal functions and governance processes. 

Security Advisories and Customer Communication 

When necessary, Bonfiglioli may issue Product Security Advisories. 
 
Advisories may include: 
• Affected products and versions 
• Severity information 
• Technical impact 
• Mitigation recommendations 
• Corrective actions 
• Availability of patches or updates 
 
Where appropriate, advisories may be communicated directly to affected customers and partners through the established channels. 

The following are generally outside the scope of the PSIRT process: 
 
• Product quality issues without cybersecurity implications 
• Functional defects unrelated to security 
• Social engineering attacks against individuals 
• Issues requiring unrealistic physical access and presenting no meaningful security impact 
• Vulnerabilities affecting standalone third-party products not integrated into Bonfiglioli products 
 
Bonfiglioli reserves the right to evaluate reports on a case-by-case basis. 

Please do not disrupt services or customer operations, access or modify data without authorization, or test systems you do not own or have permission to test. Any testing must comply with applicable laws and agreements. 

Contact 

Please use the Product Security Reporting Form available on this page. 
 
Only if the reporting portal is temporarily unavailable or additional communication is required, the Bonfiglioli PSIRT may be contacted at: psirt@bonfiglioli.com 
 
For non-security-related support requests, please use standard Bonfiglioli support channels. 
 
Last updated: July 2026 
Owner: Bonfiglioli PSIRT

Product Security Reporting Form
Use arrow keys to navigate options
Use arrow keys to navigate options
Use arrow keys to navigate options
Use arrow keys to navigate options
Use arrow keys to navigate options
Use arrow keys to navigate options
Use arrow keys to navigate options
Use arrow keys to navigate options
Use arrow keys to navigate options
Use arrow keys to navigate options

After having read the privacy disclosure:
By marking the relevant box below, I hereby authorise the company to process my contact data (information on my name, place and date of birth, tax code, address, telephone number, mobile telephone number, e-mail address) for marketing and advertising communication purposes, on promotional sales initiatives, trade fairs and events, receipt of newsletters, carried out using automated contact means (e-mail) and traditional contact means (for example, telephone call with an operator) or for market research and statistical surveys.

I may revoke my declaration of consent at any time to the Company for future marketing communications by filling this form

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.