The EU Cyber Resilience Act (CRA) at esd electronics

Connectivity requirements will undergo fundamental changes with the EU Cyber Resilience Act (CRA). In the future, all devices connected to a network will be subject to long-term obligations regarding security, updates, documentation, and the entire product lifecycle. These requirements apply to all digital products sold in the EU - regardless of where they were manufactured.

esd electronics systematically evaluates security-related information regarding its own products and publishes security advisories as needed. Through our Newsletter, we provide information on new or updated security advisories, available updates, and technical measures to address security risks.

Safety throughout the Product Life Cycle

Many of our products are used in networked automation environments. That is why we view product safety as an integral part of the entire product lifecycle.

The focus is on factual, product-related information. The goal is to enable customers to assess the relevance of a notice to their own application and to implement appropriate measures.

Receive Reports

Reports of potential product vulnerabilities are collected centrally and evaluated internally.

Evaluate technically

The product's firmware versions, drivers, and documentation are reviewed by technical experts.

Inform Customers

Confirmed security-related issues are published as security advisories as needed.

Report a Vulnerability

If you suspect a potential security vulnerability in an esd product, please send your report to:

psirt@esd.eu

This contact channel is intended for safety-related inquiries regarding esd products, firmware, drivers, software tools, or product-related documentation.

A report should include

  • Affected product and part number, if known
  • Firmware version, driver version, or software version
  • Operating system used and relevant system environment
  • Network topology or communication interfaces, if relevant
  • Description of the observed behavior
  • Steps to reproduce the issue
  • Technical impact from the reporter’s perspective
  • Logs, screenshots, configuration files, or proof-of-concept information, if available
  • Assessment of whether the vulnerability is already publicly known
  • Contact information for follow-up questions

Data-Efficient Transmission

For the technical evaluation, product-related information, reproducible observations, and technical constraints are generally sufficient.

Sensitive customer data, login credentials, personal data, or confidential information from third parties should only be provided if they are necessary for the technical analysis.

Safety Guidelines

Many esd products are used in industrial networks. Their secure integration therefore depends on the product, the system architecture, and the operating environment.

Recommended Actions

  • Logically segment industrial networks
  • Activate only the necessary services and interfaces
  • Protect management and configuration interfaces from unauthorized access
  • Use secure passwords and appropriate access policies
  • Evaluate and install available firmware, driver, and software updates
  • Secure remote access separately
  • Use security features such as encrypted communication, provided the product supports them
  • Regularly review product documentation and security advisories

System-Based Evaluation

Operators and system integrators evaluate appropriate protective measures, taking into account the specific system, network topology, threat landscape, and operational processes.

Contact

Please use the appropriate contact for security advisories, product vulnerabilities, or technical support.

Security Contact

psirt@esd.eu

For reports of potential product vulnerabilities.

Technical Support

support@esd.eu

For technical questions, driver support, and complaints.