Vulnerability Disclosure Policy
EFI is committed to identifying, assessing, and addressing security vulnerabilities in our products and services to help protect our customers and partners.
Overview
At Electronics For Imaging, Inc. (EFI), we recognize the importance of identifying and responsibly addressing security vulnerabilities in our products and services.
When a potential security vulnerability is reported by a customer, partner, security researcher, supplier, other external party, or identified internally, it is handled through EFI’s product security process.
This Vulnerability Disclosure Policy describes how EFI receives, assesses, coordinates, and addresses reports of potential security vulnerabilities.
Reporting vulnerabilities
We encourage responsible disclosure of security vulnerabilities and cybersecurity incidents in EFI products and services. If you believe you have identified a potential vulnerability or a cybersecurity incident, please report it promptly using the vulnerability reporting form at the bottom of this page.
Please provide as much technical information as reasonably possible, including the affected product, version, vulnerability description, steps to reproduce, potential impact, and any other information that can help EFI validate the issue.
In-scope vulnerabilities and products
EFI welcomes reports concerning demonstrated security vulnerabilities that could affect the confidentiality, integrity, or availability of an EFI product or service.
Examples of products and services in scope
- EFI industrial inkjet products and associated software
- EFI packaging products and associated software
- EFI textile products and associated software
- EFI display graphics products and associated software
- EFI cloud applications and services
- EFI software applications and supporting tools
- EFInsight and related software components
- Firmware, embedded software and product controllers
- Other EFI products and services where a security vulnerability is demonstrated
If you are unsure whether a product or issue is in scope, please submit the report and provide the relevant details. The EFI Security Team will determine applicability during triage.
Out-of-scope reports
To focus our resources on actionable product security vulnerabilities, EFI generally does not consider the following to be vulnerability reports unless they demonstrate a meaningful security impact to an EFI product or service:
- Vulnerabilities affecting standalone third-party products or services generally fall outside the scope of this policy. However, vulnerabilities affecting third-party components, software, libraries, firmware, or services integrated into, distributed with, or materially impacting the security of an EFI product or service remain within scope and may be evaluated under EFI’s vulnerability management process.
- Generic operating-system vulnerabilities where EFI has no product-specific security impact or responsibility
- Social engineering, phishing, or physical security attacks
- Automated scanner output without validation or evidence of security impact
- Reports based solely on security best-practice recommendations without a demonstrated vulnerability
- Network enumeration or information that is already intentionally public and does not expose a security vulnerability
- Low-impact issues that do not present a meaningful security risk
- Denial-of-service testing that could disrupt production systems, products, or services
EFI may review an otherwise out-of-scope report when the information demonstrates a significant security impact.
Vulnerability assessment
EFI uses the Common Vulnerability Scoring System (CVSS) as part of its vulnerability assessment process.
Reported vulnerabilities are evaluated based on factors such as exploitability, affected product, attack requirements, potential impact, and the conditions under which the vulnerability can be exploited.
EFI may classify vulnerabilities as Critical, High, Medium, or Low based on the overall risk assessment. A CVSS score supplied by a reporter is welcome but is not considered an official EFI severity determination.
Definitions
Actively Exploited Vulnerability: An actively exploited vulnerability is a security vulnerability for which reliable evidence exists that unauthorized malicious exploitation has occurred or is occurring.
Severe Security Incident: A severe security incident is a product security incident that may adversely affect the confidentiality, integrity, authenticity, or availability of an EFI product, service, or associated data, including: Unauthorized access to sensitive or important data; Compromise of critical product functions; Introduction, execution, or propagation of malicious code; Significant disruption of product operations or security functionality.
Response and remediation
Upon receiving a report, EFI will review the information and determine whether additional information is required. Validated reports will be tracked through EFI’s internal security vulnerability management process and assigned to the appropriate product and engineering stakeholders.
- Acknowledge: EFI acknowledges receipt of the report when a valid contact method is provided.
- Triage: The Security Team reviews and validates the reported issue.
- Assess: EFI determines applicability, severity, exploitability, and product impact.
- Coordinate: The relevant product and engineering teams are engaged for remediation.
- Remediate: EFI develops and implements an appropriate fix, mitigation, or workaround.
- Verify: The remediation is reviewed and tested as appropriate.
- Close: The report is closed after the applicable remediation and disclosure activities are completed.
Response Expectations: EFI aims to acknowledge vulnerability reports within two business days and provide an initial status update within ten business days, where sufficient information and valid contact details are provided. These timeframes are targets only and may vary depending on report complexity, severity, completeness, and investigation requirements.
EFI will inform impacted users, and where appropriate other users, of actively exploited vulnerabilities, severe security incidents, and available corrective actions, mitigations, workarounds, or security updates. Communications may be provided through security advisories, product notifications, support communications, or other appropriate channels.
Responsible disclosure
EFI asks security researchers and other reporters to act responsibly while investigating and reporting potential vulnerabilities.
- Allow EFI reasonable time to investigate, validate, and address the reported vulnerability before public disclosure.
- Do not use the vulnerability for malicious purposes.
- Do not intentionally access, modify, delete, or disclose customer data or other confidential information.
- Do not intentionally disrupt EFI products, services, systems, or the vulnerability reporting service.
- Limit testing to systems and products for which you have authorization.
- Stop testing and contact EFI if your testing unexpectedly exposes sensitive information or creates a risk of disruption.
Good-Faith Security Research: EFI values good-faith security research conducted in accordance with this policy. EFI does not intend to pursue legal action against researchers who act in good faith, comply with this policy, responsibly report vulnerabilities, and avoid activities that could harm EFI, its customers, or third parties. This protection does not extend to activities involving: Privacy violations; unauthorized access to customer or third-party data; service disruption; extortion or coercion; social engineering; persistence mechanisms; destructive testing; activities exceeding what is reasonably necessary to demonstrate a vulnerability.
Coordination with security researchers
EFI values the contributions of security researchers and other members of the security community who help us identify and address vulnerabilities.
Where appropriate, EFI will work with reporters to clarify, reproduce, and validate reported vulnerabilities and coordinate remediation and disclosure.
Bug bounty and recognition
EFI does not currently operate a formal bug bounty program.
There is no expectation of payment or other financial compensation for submitting a vulnerability report. Where a vulnerability is newly reported and validated by EFI, EFI may, at its discretion, recognize the contributing researcher in an applicable security advisory or other public communication, subject to the researcher’s preferences and applicable legal and privacy requirements.
Public disclosure
EFI supports coordinated and responsible vulnerability disclosure. Once an appropriate remediation, mitigation, or security update is available, EFI generally provides vulnerability information through security advisories or other appropriate communications. Such communications may include Affected products and versions; vulnerability description; severity and potential impact; available remediation, mitigation, or workaround information; and relevant identifiers, including CVE references where applicable.
EFI may delay public disclosure when immediate publication could increase security risk, facilitate exploitation, interfere with remediation activities, or otherwise adversely impact customers or the security community.
Cyber Resilience Act (EU) compliance and regulatory reporting
EFI assesses reported vulnerabilities and product security incidents to determine whether customer communication, public disclosure, or regulatory notification is required. Where applicable, including under Regulation (EU) 2024/2847 (Cyber Resilience Act), EFI maintains processes to identify, assess, escalate, and manage actively exploited vulnerabilities and severe security incidents affecting products with digital elements. EFI maintains procedures designed to support applicable regulatory reporting obligations, coordination with relevant authorities, and communication with affected users. EFI may coordinate with Computer Security Incident Response Teams (CSIRTs), ENISA, component suppliers, customers, security researchers, and other stakeholders as appropriate to facilitate vulnerability remediation and responsible disclosure.
Technical support
This vulnerability reporting process is intended for reporting potential security vulnerabilities. It is not a technical support channel for product usage, configuration, or general troubleshooting.
For non-security-related product assistance, please use EFI’s applicable customer or technical support channels.
Continuous improvement
EFI is committed to continuously improving the security of its products, services, and vulnerability management processes. We periodically review this policy and related procedures to address emerging threats, regulatory expectations, and industry practices.
If you believe you have identified a security vulnerability in an EFI product or service, please complete the form below and provide as much information as possible. The EFI Security Team will review reports that may affect EFI products and services.
Secure submission requirements
Please do not submit:
- Malware, ransomware or intentionally malicious files
- Executable files, scripts or other code intended to execute on EFI systems
- Credentials, passwords, API keys, tokens or other secrets
- Customer data, personal data or confidential information
- Content intended to compromise, disrupt or poison the reporting service
If additional evidence is required to investigate a report, EFI may provide a separate secure mechanism for submitting supporting material.
Report a potential vulnerability
Report a potential vulnerability
If you believe you have identified a security vulnerability in an EFI product or service, please complete the form below and provide as much information as possible. The EFI Security Team will review reports that may affect EFI products and services.
Important: This form does not accept file attachments. Do not include passwords, credentials, customer data, personal data, confidential information, malware, or executable content in your submission.
Thank you for your interest in EFI.
One of our representatives will contact you shortly.