Coordinated Vulnerability Disclosure (CVD)

Coordinated Vulnerability Disclosure (CVD) is a structured process in which security vulnerabilities in software or systems are first reported confidentially to the manufacturer or provider concerned. The manufacturer or provider is then given a reasonable period of time to rectify the vulnerability before it is made public. The aim is to minimise risks to users by rectifying the vulnerability before it can be exploited.

You can report vulnerabilities in BUW’s IT products, IT systems or IT services to us. You can find our contact details in our security.txt file

Reports that have helped us to resolve vulnerabilities are mentioned in our Acknowledgements.