Product Security Advisory and Vulnerability Disclosure
Galdi's Commitment to Digital Product Security
Galdi considers cybersecurity a fundamental element of the quality and reliability of its products. For this reason, we adopt structured processes for managing vulnerabilities and security incidents that may impact our products with digital elements.
In accordance with the obligations set out in Regulation (EU) 2024/2847 (Cyber Resilience Act), this page serves as the official public channel through which Galdi communicates information regarding security vulnerabilities and incidents that require dissemination to product users.
Purpose of this page
- Security advisories relating to vulnerabilities identified in Galdi products;
- Communications regarding actively exploited vulnerabilities;
- Information about security incidents that may affect product security;
- Temporary mitigation measures;
- Software, firmware, or other corrective updates that are available;
- Operational instructions for customers, partners, and end users.
Communication Timeline
If Galdi becomes aware of an actively exploited vulnerability or a serious incident involving one of its products with digital elements, communications published on this page will, where applicable, follow the timelines established by European regulations.
Information may be published progressively, starting with a preliminary communication and subsequently supplemented with additional technical details and operational guidance as analysis and mitigation activities progress.
In some cases, for security reasons, certain technical information may be temporarily omitted or limited in order to avoid increasing the risk of exploitation of the vulnerability.
Content of Security Advisories
Each Product Security Advisory may include:
- Advisory identifier;
- Publication and update dates;
- Affected product;
- Affected versions;
- Severity level;
- Description of the event or vulnerability;
- Potential impacts;
- Recommended mitigation measures;
- Availability of corrective updates;
- Status of remediation activities.
Reporting Vulnerabilities to Galdi
Security researchers, customers, partners, and other interested parties may report vulnerabilities concerning Galdi products using the contact details provided below.
Dedicated e-mail: security@galdi.it
Recommended subject line: "Security Vulnerability Report"
Reports received will be analyzed by the responsible technical teams in accordance with internal vulnerability management procedures.
Limitations of Published Information
Communications published on this page are intended to inform and protect product users.
Galdi reserves the right not to disclose technical details whose publication could:
- Facilitate further attacks;
- Compromise customer security;
- Expose confidential information or personal data;
- Interfere with ongoing investigation or analysis activities.
Advisory Archive
All published security advisories will remain available in this section of the website to enable historical consultation of communicated vulnerabilities and incidents.
Contacts
For requests related to product security, vulnerability management, or communications published on this page, please contact:
Galdi S.r.l.
Product Security Team
security@galdi.it
Legal Notice
The information published on this page constitutes Galdi's official public communication channel for security aspects related to products with digital elements. Users are encouraged to consult this section periodically to check for new advisories, updates, or corrective measures.