CVE Numbering Authority (CNA)

Since April 2020 CERT@VDE is an authorized CVE Numbering Authority (CNA) and authorized to issue CVE-IDs.

Scope of validity

Our Scope is defined as follows:

  • Our partner Brands and Vendors:
  • Industrial and infrastructure control systems (and its components) of European Union (EU) based vendors as long as there is no CNA with a more specific scope for the vulnerability (see mitre.org)

Request or update a CVE-ID

Before filling out the form, make sure that this vulnerability falls under the responsibility of CERT@VDE. You can proceed as follows:

  • send an email, optionally PGP encrypted, to info@certvde.com. Our PGP Public-Key is available for download here.
  • or via our contact form:

Our partner Brands and Vendors

365FarmNet, ads-tec Industrial IT, AKG, AMX, AUMA, Baade, Balluff, Beckhoff, Bender, Bucher Automation, Carlo Gavazzi Controls, CLAAS, Codesys, Draeger, DURAG GROUP, Endress+Hauser, Euchner, Festo, Frauscher, GEA, Grob, Harman, Helmholz, Hilscher, HIMA, Hydac, ifm, Innominate, Janitza, JBL, Jetter, JUMO, K4 DIGITAL, KEB, KEBA, Kendrion, Krohne, Kuka, Lenze, M&M Software, MB connect line, Mettler Toledo, Miele, Murrelektronik, NEOCEPTION, Pepperl+Fuchs, Phoenix Contact, Pilz, Satinfo, Sauter, SMA, SWARCO, Sysmik, Trumpf, TTControl, VARTA Storage, VEGA, VMT Vision Machine Technic, WAGO, Weidmueller, Welotec, Wiesemann & Theis, WIKA, Yaskawa.