上报方式

本公司目前通过 加密邮箱 接收漏洞上报。请下载《疑似漏洞上报模板》填写后,使用我们的 OpenPGP 公钥加密附件,发送至安全邮箱:psirt.zz@crrcgc.cc

上报步骤

  1. 下载《疑似漏洞上报模板》(附件2),按照模板要求填写:①个人或组织信息 ②漏洞信息(受影响产品或组件、简要描述、技术细节、攻击场景、修复建议)③漏洞披露意向 ④是否允许对外致谢 ⑤其它信息。
    下载《疑似漏洞上报模板》
  2. 下载 OpenPGP 公钥,用于加密包含敏感信息的附件。
    下载 OpenPGP 公钥
    公钥指纹:5914 81D5 183D 5E59 45B5 1717 9C38 C210 2ECD B06C
  3. 加密附件:使用 GnuPG 等工具以公钥加密包含漏洞信息的文件。
  4. 发送邮件至安全邮箱,邮件正文可包含简要说明(无需加密),附件必须加密。
  5. 等待回执:我们将在 24 小时内向您发送书面回执,包含工单编号。

OpenPGP 加密操作示例

# 导入公钥
gpg --import pgp-key.asc

# 加密漏洞报告文件(生成 vulnerability-report.docx.gpg)
gpg --encrypt --recipient PSIRT --output vulnerability-report.docx.gpg vulnerability-report.docx

# 将 .gpg 加密文件作为附件发送至安全邮箱即可

响应时效(SLA)

环节时效承诺说明
初次回执24 小时内确认邮件,告知工单编号及后续流程
首次技术反馈5 个工作日内漏洞验证状态、初步评估结果
漏洞确认通知验证完成后 3 个工作日内漏洞有效性、风险等级及预计修复时间
修复进度同步每 15 个工作日至少一次禁言期内定期同步修复进展
公告发布通知公告发布当日公告链接及致谢说明

协同披露规则(禁言期 90 天 / 延期 ≤30 天 / 提前披露情形)详见漏洞披露政策

上报须知

  • 我们建议对包含漏洞细节、复现步骤等敏感信息的附件进行 OpenPGP 加密后提交。
  • 您的个人信息(如联系邮箱)仅用于漏洞处理与回执,将按照隐私政策进行保护。
  • 如涉及个人数据,请同时知悉我们的隐私政策

处理流程总览

我们遵循 ISO/IEC 30111《漏洞处置流程》,对上报的漏洞按照以下流程处理:

  1. 统一渠道接收
    外部研究者、客户等通过安全邮箱向公司发送产品漏洞信息,统一由 PSIRT 渠道接收。
  2. 创建唯一漏洞工单
    对接收的漏洞信息进行工单建档,记录漏洞上报人、描述、复现步骤、受影响产品及版本等内容。
  3. SLA 限时回执
    向上报者发送书面确认回执,包含工单编号及初次反馈逾期时间。
  4. 权限隔离与保密管控
    确定漏洞处理团队权限,对漏洞信息进行保密处理,仅限必要人员访问。
  5. 初步分流判定
    针对上报的漏洞进行初步判定,根据判定结果转发至不同的处理流程(验证、修复等)。
  6. 验证与修复
    对漏洞进行验证与影响评估,制定并实施修复方案。
  7. 披露与公告
    在修复完成后,按照负责任披露原则与行业惯例发布安全公告。

上报入口

如果您发现了潜在的安全漏洞,请通过漏洞上报指引提交,我们将按上述流程处理。

1. 政策声明

中车株洲电力机车有限公司 高度重视产品安全,欢迎并感谢安全研究者、合作伙伴及用户向我们负责任地报告产品安全漏洞。我们承诺:

  • 对每一份漏洞报告给予认真对待和及时响应;
  • 在漏洞修复前,严格保护报告者信息及漏洞细节,不因漏洞报告对研究者采取法律行动;

我们倡导负责任的漏洞披露行为,期望报告者遵守协同披露规则,在漏洞修复完成前不对外公开漏洞细节,共同保护广大用户的安全。

2. 漏洞上报渠道

中车株洲电力机车有限公司 提供以下漏洞上报渠道,报告者可选择最便捷的方式提交:

【加密通信说明】 涉及漏洞利用代码、敏感配置等高危信息时,强烈建议使用 PGP 加密邮件提交。PGP 公钥指纹及下载地址详见官网漏洞上报网页。初次报告可使用普通渠道,后续沟通由 PSIRT 引导切换至加密通道。

3. 响应时效

环节时效承诺说明
初次回执收到报告后 24 小时内发送确认邮件,告知工单编号及后续流程
首次技术反馈收到报告后 5 个工作日内告知漏洞验证状态、初步评估结果
漏洞确认通知验证完成后 3 个工作日内确认漏洞有效性、风险等级及预计修复时间
修复进度同步每 15 个工作日至少一次禁言期内定期同步修复进展
公告发布通知公告发布当日向报告者发送公告链接及致谢说明

4. 协同披露规则

公司遵循协同漏洞披露(CVD)原则,与报告者共同约定漏洞公开时间,确保在用户获得有效防护后再公开漏洞细节。

4.1 默认禁言期

  • 标准禁言期为 90 天,自漏洞确认之日起计算;
  • 严重级漏洞(CVSS ≥ 9.0)且已出现利用迹象的,可缩短至 30 天;
  • 低危漏洞可根据实际情况适当延长。

4.2 禁言期延期

  • 因修复复杂度高、供应链协同等原因无法按期修复的,公司将提前向报告者说明原因并申请延期;
  • 延期原则上不超过 30 天,特殊情况双方协商确定;
  • 公司将在延期期间保持定期进度同步。

4.3 提前披露情形

出现以下情形之一时,公司可提前向用户和漏洞上报者发送安全通知:

  • 漏洞已被公开披露或在野外被大规模利用;
  • 存在重大安全风险,需紧急提醒用户采取防护措施;
  • 其他经评估认为提前披露更有利于整体安全的情形。

免责条款

对本网站的内容,我们已尽最大努力的审核,但不提供任何形式的明示的或默示的关于内容的正确性、及时性、有效性、稳定性、可用性、不侵犯他人权利等方面的保证;不保证服务器的稳定性,不保证您任何时候均可浏览、阅读、复制、使用本网站;不保证网站内容所包含的文字、图形、材料、链接、说明、陈述或其它事项的准确性或完整性,也不保证本网站的内容不存在打印、复制及其他输入方面的错误。中国中车或经中国中车书面授权人士可随时更改本网站内容,无须另作通知,但并不保证在内容变化时及时更新,也不保证在更新时通知您。

在任何情况下,对于因使用本网站内容或无法进入本网站而导致的任何直接的、间接的、附带的、给第三人造成的损失包括但不限于利润损失、信息数据丢失、财产毁坏等损失,本网站均无须承担法律责任,不论是采用合同之诉、侵权之诉或其他诉讼理由。

通过本站点的链接是为用户提供方便,但链接的网站不在本站点的控制范围内,任何用户通过本站点的链接浏览其他网站被认为没有浏览本站点,因而对从链接的网站收到的网络传送或任何其他形式的传输不承担任何责任。

保护用户隐私权

我们尊重广大用户的隐私,未经用户的同意,我们不搜集用户的资料。对于因服务的需要而掌握的用户的电子邮件、信息和地址我们承诺非经用户允许,不向任何第三方提供。

终止条款

协议在有任意一方提出终止时即失效。无论是否在此协议所规定的条款下或其他情况下,只要你将所有的从本网站获得的软件、文件和一切相关材料销毁,即构成本协议的终止。

其他

由于本网站而引起的一切诉讼或争议均应适用中华人民共和国法律,任何有关本网站和网站声明的争议,应由中国中车住所地有管辖权的人民法院管辖。如中华人民共和国法律的修改使上述任何条款成为非法,各方将同意由中国中车对上述条款作出修改。

CRRC Zhuzhou Electric Locomotive Co., Ltd. PSIRT

The Product Security Incident Response Team (PSIRT) of CRRC Zhuzhou Electric Locomotive Co., Ltd. is a dedicated team responsible for receiving, verifying and disclosing security vulnerabilities in our products. We encourage security researchers, industry organizations, customers and suppliers to report potential product vulnerabilities to us. We handle vulnerabilities in accordance with ISO/IEC 30111 and ISO/IEC 29147.

Report a Vulnerability

If you have identified a potential security vulnerability in our products, please follow the reporting guide. We recommend using the report template and OpenPGP encryption to protect your information.

View Reporting Guide →

Vulnerability Handling Process

From receipt, ticket creation, SLA acknowledgement, verification to remediation and disclosure, we have established a standardized and auditable vulnerability lifecycle management process.

View Process →

Vulnerability Disclosure Policy

We follow responsible disclosure principles, defining management requirements for each stage from discovery, receipt, verification, remediation to disclosure.

View Policy →

Contact Us

For any questions regarding product security, please contact us

PSIRT Contact

Security Email: psirt.zz@crrcgc.cc

Please encrypt sensitive information (e.g. vulnerability details, reproduction materials) with our OpenPGP public key before sending. See the reporting guide.

Security Advisories

Announcements on product security vulnerabilities and security incidents

No announcements yet

How to Report

We currently accept vulnerability reports via encrypted email. Please download the Vulnerability Report Template (Annex 2), fill it in, encrypt it with our OpenPGP public key, and send it to: psirt.zz@crrcgc.cc.

Reporting Steps

  1. Download the Vulnerability Report Template (Annex 2) and fill it in: 1) Personal or organization information 2) Vulnerability information (affected product or component, brief description, technical details, attack scenario, remediation suggestions) 3) Disclosure intent 4) Consent to public acknowledgement 5) Other information.
    Download the Vulnerability Report Template
  2. Download the OpenPGP public key, used to encrypt attachments containing sensitive information.
    Download the OpenPGP Public Key
    Key fingerprint: 5914 81D5 183D 5E59 45B5 1717 9C38 C210 2ECD B06C
  3. Encrypt the attachment: use tools such as GnuPG with the public key to encrypt the file containing vulnerability information.
  4. Send the email to the security mailbox. A brief description may be included in the email body (no encryption required); attachments must be encrypted.
  5. Await acknowledgement: we will send you a written acknowledgement within 24 hours, including a ticket ID.

OpenPGP Encryption Example

# Import the public key
gpg --import pgp-key.asc

# Encrypt the vulnerability report file (generates vulnerability-report.docx.gpg)
gpg --encrypt --recipient PSIRT --output vulnerability-report.docx.gpg vulnerability-report.docx

# Send the .gpg encrypted file as an attachment to the security mailbox

Response Times (SLA)

StageCommitmentDescription
Initial acknowledgementWithin 24 hoursConfirmation email with ticket ID
First technical feedbackWithin 5 business daysVerification status and initial assessment
Vulnerability confirmationWithin 3 business days after verificationValidity, risk level, estimated fix time
Progress updatesAt least every 15 business daysRegular sync during the embargo period
Advisory noticeOn the publication dayAdvisory link and acknowledgement

Coordinated disclosure rules (90-day embargo / extension up to 30 days / early disclosure scenarios) are detailed in the vulnerability disclosure policy.

Notes

  • We recommend encrypting attachments containing sensitive information such as vulnerability details and reproduction steps with OpenPGP before submission.
  • Your personal information (e.g. contact email) is used solely for vulnerability handling and acknowledgement, and is protected in accordance with our privacy policy.
  • If personal data is involved, please also be aware of our privacy policy.

Process Overview

We follow ISO/IEC 30111 to handle reported vulnerabilities through the following process:

  1. Centralized receipt
    External researchers, customers and others send product vulnerability information to the company via the security mailbox, received centrally by PSIRT.
  2. Create a unique vulnerability ticket
    Document the received information into a ticket, recording the reporter, description, reproduction steps, affected product and version.
  3. SLA acknowledgement
    Send a written acknowledgement to the reporter, including the ticket ID and initial feedback due time.
  4. Access control and confidentiality
    Define the handling team permissions and apply confidentiality controls so that only necessary personnel have access.
  5. Initial triage
    Perform an initial assessment of the reported vulnerability and route it to the appropriate handling workflow (verification, remediation, etc.).
  6. Verification and remediation
    Verify and assess the impact of the vulnerability, then develop and implement a remediation plan.
  7. Disclosure and advisory
    Once remediation is complete, publish security advisories in line with responsible disclosure principles and industry practice.

Reporting Entry

If you have identified a potential vulnerability, please submit it via the vulnerability reporting guide and it will be handled according to the above process.

1. Policy Statement

CRRC Zhuzhou Electric Locomotive Co., Ltd. takes product security seriously and welcomes responsible reports of product security vulnerabilities from security researchers, partners and users. We commit to:

  • Treat every vulnerability report seriously and respond in a timely manner;
  • Strictly protect reporter information and vulnerability details before remediation, and take no legal action against researchers for reporting;

We advocate responsible disclosure and expect reporters to follow coordinated disclosure rules, not publicly disclosing vulnerability details before remediation is complete, to protect all users.

2. Reporting Channels

[Encrypted Communication] For high-risk information such as exploit code or sensitive configurations, we strongly recommend submitting via PGP-encrypted email. The PGP public key fingerprint and download address are available on the vulnerability reporting page. Initial reports may use normal channels; PSIRT will guide you to switch to an encrypted channel for follow-up.

3. Response Times

StageCommitmentDescription
Initial acknowledgementWithin 24 hoursConfirmation email with ticket ID and next steps
First technical feedbackWithin 5 business daysVerification status and initial assessment
Vulnerability confirmationWithin 3 business days after verificationValidity, risk level and estimated fix time
Remediation progress updatesAt least every 15 business daysRegular progress sync during embargo period
Advisory publication noticeOn publication dayAdvisory link and acknowledgement

4. Coordinated Disclosure Rules

The company follows Coordinated Vulnerability Disclosure (CVD) principles, agreeing on public disclosure timing with reporters to ensure users have effective protection before details are public.

4.1 Default Embargo Period

  • Standard embargo period: 90 days from vulnerability confirmation;
  • Critical vulnerabilities (CVSS ≥ 9.0) with signs of exploitation may be shortened to 30 days;
  • Low-severity vulnerabilities may be extended as appropriate.

4.2 Embargo Extension

  • If remediation cannot be completed on time due to complexity or supply chain coordination, the company will explain and request an extension in advance;
  • Extensions are normally no more than 30 days; special cases subject to mutual agreement;
  • Regular progress updates will be maintained during the extension.

4.3 Early Disclosure

The company may send security notifications to users and reporters in advance under any of the following circumstances:

  • The vulnerability has been publicly disclosed or is being exploited at scale in the wild;
  • A major security risk requires urgent user action;
  • Other circumstances where early disclosure is assessed to be in the best interest of overall security.

Disclaimer

While we have made every effort to review the content of this website, we provide no warranties of any kind, express or implied, regarding the correctness, timeliness, validity, stability, availability, or non-infringement of third-party rights of the content. We do not warrant the stability of the server, nor that you will be able to browse, read, copy or use this website at any time. We do not warrant the accuracy or completeness of the text, graphics, materials, links, descriptions, statements or other matters contained in the website content, nor do we warrant that the content of this website is free from errors in printing, copying or other input. CRRC Corporation Limited (中国中车) or persons authorized in writing by CRRC Corporation Limited may change the content of this website at any time without further notice, but neither warrants that such content will be updated in a timely manner upon change, nor that you will be notified upon update.

In no event shall this website be liable for any direct, indirect, incidental, or third-party damages arising from the use of the content of this website or the inability to access this website, including but not limited to loss of profits, loss of information or data, and destruction of property, whether based on contract, tort, or any other grounds of action.

Links on this website are provided for the convenience of users, but linked websites are not under the control of this website. Any user browsing other websites through links on this website is deemed not to be browsing this website, and therefore no responsibility is assumed for network transmissions or any other forms of transmission received from linked websites.

Protection of User Privacy

We respect the privacy of our users and do not collect user data without the user's consent. We undertake not to provide to any third party the emails, information and addresses of users obtained for the needs of the service, unless permitted by the user.

Termination

This agreement shall cease to be effective upon termination proposed by either party. Whether under the terms set out in this agreement or under other circumstances, once you destroy all software, files and all related materials obtained from this website, this agreement shall be deemed terminated.

Miscellaneous

All lawsuits or disputes arising out of this website shall be governed by the laws of the People's Republic of China. Any dispute relating to this website and the statements on this website shall be subject to the jurisdiction of the competent people's court at the domicile of CRRC Corporation Limited (中国中车). If amendments to the laws of the People's Republic of China render any of the above terms illegal, the parties agree that CRRC Corporation Limited (中国中车) shall make modifications to the above terms.

中车株洲电力机车有限公司 PSIRT

中车株洲电力机车有限公司 产品安全应急响应团队(Product Security Incident Response Team,简称 PSIRT)是专职团队,负责公司产品相关安全漏洞的接收、核查与披露。我们鼓励安全研究人员、行业组织、客户与供应商将识别到的产品安全漏洞报告给我们,我们将遵循 ISO/IEC 30111、ISO/IEC 29147 等标准处理相关漏洞。

漏洞上报

如果您发现了与公司产品相关的潜在安全漏洞,请通过上报指引提交。建议使用漏洞上报模板并采用 OpenPGP 加密,确保信息安全。

查看上报指引 →

漏洞处理流程

从接收、建档、SLA 回执、核查验证到修复披露,我们建立了标准化、可审计的漏洞全生命周期管理流程。

查看处理流程 →

漏洞披露政策

我们遵循负责任的漏洞披露原则,明确漏洞从发现、接收、验证、修复到披露的各阶段管理要求。

查看披露政策 →

联系我们

关于产品安全漏洞的任何问题,欢迎通过以下方式与我们联系

PSIRT 联系邮箱

安全邮箱:psirt.zz@crrcgc.cc

发送敏感信息(如漏洞细节、复现材料)前,请务必使用我们的 OpenPGP 公钥进行加密,详见上报指引

安全公告

公司产品安全漏洞及安全事件公告

暂无公告