Report a security issue

Use this page to tell Biamp about a vulnerability in one of our products, or about a system you believe has been compromised. Reports are read by the Biamp Product Security Incident Response Team. You do not need an account, and you do not have to tell us who you are.


A vulnerability is a flaw that could be used against a system. A compromise means you believe a system has already been broken into or is behaving as though someone else is controlling it. If you are not sure which one you have, pick the closest and describe it below — we will sort it out.

What are you reporting?

NOTE: A flaw in software Biamp did not write but includes in its products — an open-source library, embedded OS, or licensed component. Use this if you found the issue in a component, or if a published CVE affects a version Biamp is shipping. Tell us the component and version if you know it.

Is this vulnerability being actively exploited?


"Actively exploited" means you have seen the flaw used against a real system, or you have evidence that it has been — not that you have shown it could be. A working proof of concept on your own bench is not active exploitation. If you are unsure, choose I don't know; it is a real answer and we treat it differently from "no".

Reporter

You can report anonymously. We never reject a report because we do not know who sent it. But without an email address we cannot acknowledge your report, cannot ask you follow-up questions, and cannot tell you when it is fixed.

Classification and Disclosure

Is this already publicly known?

Do you plan to disclose publicly?

Does this involve a third-party component?

Affected Product

We ask because a report from a country we do not expect the product to be in is a signal worth chasing, and because it helps us judge how many customers are affected. Skip it if you would rather not say.

Where is the affected system deployed?

Technical detail

What does an attacker need?

Attachments

This field is required

Attachments may be screenshots, logs, or anything associated with the exploit. (Max file size: 50 MB)

Add another

Suspected compromise

Is it still happening?

What has been affected?

Has the affected party been told?


Review our privacy policy

Encrypt it if you like
Use our PGP key so you never have to send unpatched detail in the clear. You may email us at security@biamp.com.

Download the public key

Learn more about PGP

Supported Languages
Responses should be submitted in English. Submissions in other languages may cause a delay.