Our Commitment to Security

At koenig-pa GmbH, we take product security seriously and are committed to identifying, assessing, and addressing vulnerabilities in a timely manner.
We welcome responsible vulnerability reports from customers, partners, security researchers, and other members of the security community.

Reporting a Vulnerability

If you believe you have identified a potential security vulnerability in one of our products, please contact us at:
security@koenig-pa.de

Please include, where possible:

  • Product name and version
  • Description of the issue
  • Steps required to reproduce the problem
  • Potential security impact
  • Logs, configuration examples, crash dumps, or proof-of-concept information

We kindly request that vulnerability details are not publicly disclosed until the issue has been investigated and the disclosure process has been coordinated.

Vulnerability Handling Process

We handle vulnerability reports in accordance with our Coordinated Vulnerability Disclosure (CVD) process.

Upon receiving a report, we will:

  1. Acknowledge receipt of the report.
  2. Investigate and validate the issue.
  3. Assess its impact on affected products and users.
  4. Develop a remediation or mitigation where appropriate.
  5. Keep the reporter informed when possible.
  6. Coordinate disclosure activities as required.

Customer Notification

If a confirmed vulnerability affects supported product versions, customers may be notified through:

  • Customer Support Portal
  • Support Ticketing System
  • Security Advisories
  • Email Notifications

The notification method depends on the nature of the vulnerability and the affected products.

Security Advisories

Information regarding confirmed vulnerabilities and related fixes may be published through Security Advisories.

Security Advisories may include:

  • Affected products and versions
  • Impact description
  • CVE identifier, where applicable
  • Mitigation recommendations
  • Fixed product versions

Example

Security Advisory SA-2026-001

  • Product: KPA EtherCAT Master
  • Severity: High
  • CVE: CVE-2026-XXXX
  • Fixed in Version: 1.8.4

Security Documentation

For supported products, the company may provide security-related documentation, including:

  • Security Advisories
  • Supported Version Information
  • Details of Security Fixes
  • Software Bill of Materials (SBOM), where applicable
  • Other Relevant Technical Information

Contacts

Security Reports
security@koenig-pa.de

Technical Support
support@koenig-pa.de