Skip to content

Verizon/cve

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

1 Commit
 
 

Repository files navigation

Vulnerability Disclosure Program (VDP)

Scope

The scope of the Verizon VDP includes Verizon products and Verizon-supported products and is intended for the reporting of vulnerabilities. For example, Verizon-branded devices such as mobile hot spots, fiber routers, Verizon phone applications (e.g., My Verizon), etc.

At the present time Verizon does not investigate nor report vulnerabilities for other vendors, products, or services. Verizon commits to the following:

  1. Make all reasonable attempts to notify OEM suppliers of any vulnerabilities for Verizon-branded products.
  2. In the event of a vulnerability report for an OEM product, Verizon will forward vulnerability reports to the appropriate supplier.
  3. Reports submitted to Verizon will be analyzed by the appropriate internal security teams, verified, and disclosed via CISA as a CVE.
  4. Response times will vary depending on the type of vulnerability, but will generally be within 5 business days.
  5. Not publicly disclose a vulnerability while the supplier develops a fix or mitigation (or until 90 days have expired, whichever comes first).
  6. Coordinate the Public Disclosure date and publishing vulnerability advisories with the supplier. Disclosure consists of a published CVE as well as documentation located on the Verizon CVE page.

About

CVEs advisories that Verizon publishes as a CVE Numbering Authority

Resources

Stars

Watchers

Forks

Contributors