(A) Introduction Delta places a high priority on product security and is committed to establishing a robust mechanism for reporting, handling, and disclosing product security vulnerabilities. We strive to provide our customers and users with reliable product security guidance and resolutions (or mitigations) in a timely, transparent, and credible manner, thereby minimizing product security risks. To achieve this, Delta has established the Product Security Incident Response Team (Delta PSIRT) as the dedicated entity responsible for receiving and handling product security vulnerabilities reported by external parties.
This Policy outlines Delta’s principles for handling externally reported product security vulnerabilities, covering acknowledgment of receipt, triage and analysis, investigation, verification of remediation or mitigation measures, and coordinated vulnerability disclosure. Internal product security management activities within Delta—such as secure development, internal testing, and auditing—are governed by separate internal regulations and fall outside the scope of this policy.
Delta PSIRT continuously aligns with widely adopted international and industry best practices and standards, specifically ISO/IEC 29147 and ISO/IEC 30111, to refine its operations regarding vulnerability reporting, handling, and coordinated vulnerability disclosure (CVD).
(B) Scope of Application and Support Commitment This policy applies to the reporting of product security vulnerabilities for all Delta-branded products sold externally (hereinafter referred to as the "Products"). For Delta ODM or OEM products, vulnerability handling will be conducted in accordance with the corresponding terms of the respective agreements.
Security Support Period: For supported products, Delta commits to continuously providing product security vulnerability handling and maintenance services within the officially announced security support period.
Security Updates and Mitigations: Security updates or mitigation measures intended to reduce the risks posed by security vulnerabilities will, in principle, be provided free of charge to affected users.
(C) How to Report Product Security Vulnerabilities
If you discover a potential security vulnerability in a Delta product, please submit a product security vulnerability report through one of the following official security reporting channels:
Product Security Vulnerability Reporting Webpage (Secure HTTP Transmission): You may submit your report through Delta’s official Product Security Vulnerability Reporting webpage. This web-based reporting channel requires the use of Hypertext Transfer Protocol Secure (HTTPS), ensuring that the product security vulnerability report and contact information you submit are encrypted during transmission.
Email (Supporting S/MIME Cryptographic Encryption): You may also mail your vulnerability report directly to Delta PSIRT’s official email address at Delta.PSIRT@deltaww.com. To protect the security of product vulnerability reporting information during email transmission, Delta uses S/MIME (Secure/Multipurpose Internet Mail Extensions) to encrypt email content. (Download Delta S/MIME Public Key; Fingerprint: 7098509e2c41abd9974137a23d5b54b76389c0b9)
Anonymous Reporting and Cooperative Handling: To encourage product security research, Delta welcomes and accepts anonymous vulnerability reports. If the provided technical details are insufficient to reproduce or verify the vulnerability during the initial assessment, Delta PSIRT will reach out to request supplementary information and collaborate with you to confirm the issue. Delta will not reject any report solely because the reporter chooses to remain anonymous.
When reporting a product security vulnerability, please include the following information to the fullest extent possible. This will facilitate our assessment of the issue and determine its scope of impact. Items marked with an asterisk (*) are required:
Model Name *
Part Number (P/N)
Serial Number (S/N)
Software / Firmware Version *
Vulnerability Description *
Steps to Reproduce *
Common Weakness Enumeration (CWE) ID
Common Vulnerabilities and Exposures (CVE) ID
CVSS Score
CVSS Vector String
(D) Product Security Vulnerability Handling and Coordinated Vulnerability Disclosure Process Delta’s product security vulnerability management process strictly follows the internationally recognized principles of Coordinated Vulnerability Disclosure (CVD). CVD refers to a controlled and continuously coordinated process involving the reporter, the manufacturer, and relevant stakeholders before a vulnerability is publicly disclosed, so that the vulnerability can be confirmed, handled, and securely disclosed at an appropriate time, thereby reducing the risk of improper exploitation. To ensure the secure transmission of technical information at each stage and consistent communication among all parties, Delta has established the following handling process:
Acknowledge Receipt of a Report: After receiving an external vulnerability report regarding a Delta product, Delta PSIRT will generally respond within two business days and provide a case tracking number to ensure traceability for subsequent communications. Where national regulations apply, Delta will handle the matter in accordance with the applicable product cybersecurity vulnerability reporting requirements.
Triage and Analysis: Delta PSIRT triages and analyzes the potential cybersecurity vulnerability and conducts an initial assessment of its impact on Delta products, including whether other product lines, components, or related assets may also be affected.
Investigation: Delta PSIRT will work with the product development teams to identify the root cause and the actual scope of impact of the vulnerability.
Mitigation: Delta will develop and test security updates or mitigation measures. Where technically feasible, product security updates will be released separately from product feature updates.
Disclosure: After the security update or mitigation measures have been verified, Delta will publish a Product Security Advisory. Prior to publication, Delta and the reporter shall jointly observe an embargo period to prevent premature disclosure of technical exploitation details related to the product security vulnerability, thereby protecting product users.
Post-Release and Monitoring: After the security update is released, Delta will continue to monitor the effectiveness and compatibility of the security update or mitigation measures in real-world environments, and will feed the lessons learned back into the product security design process for continuous improvement.
(E) Rate the Severity and Impact of Vulnerabilities Delta PSIRT and product development team leverages the Common Vulnerability Scoring System (CVSS) to assess the potential risks of a vulnerability issue.
CVSS is a method used to supply a qualitative and quantitative measure of severity, and considers several factors, including the level of effort required to exploit a vulnerability as well as the potential impact should the vulnerability be exploited.
After analyzing the vulnerability issue, Delta will summarize the assessed impact of a vulnerability by way of a numeric score, vector string, and qualitative severity ratings (i.e., one of Critical, High, Medium, Low), as per the scale provided below:
Severity
CVSS 3.X/4.0 Score
Critical
9.0 – 10
High
7.0 – 8.9
Medium
4.0 – 6.9
Low
0.1 – 3.9
None
0.0
(F) Reporter Acknowledgment Delta values the contributions of external reporters to our product security. Although Delta does not currently operate a bug bounty program, Delta will acknowledge reporters who comply with this Policy and assist Delta in confirming, remediating, or mitigating vulnerabilities.
When a relevant security vulnerability has been remediated or mitigated and Delta publishes a Product Security Advisory, Delta may, with the reporter’s consent, include the reporter’s name, organization name, or alias in the advisory as an acknowledgment. Delta PSIRT reserves the final right to determine whether acknowledgment will be provided, the form of acknowledgment, and the content to be disclosed, based on the circumstances of each case, the reporter’s preference, applicable legal requirements, confidentiality obligations, and product security risks.
If the vulnerability has not yet been remediated, may pose significant security risks, is subject to confidentiality restrictions, or is otherwise unsuitable for public disclosure, Delta may delay, limit, or withhold the related acknowledgment information.
(G) Disclaimer
This Policy is subject to change without prior notice, and Delta reserves the right of final interpretation. Except for the mandatory product security reporting and handling obligations required by applicable national laws and regulations, the measures described herein are adopted by Delta to strengthen product security.
Delta only commits to providing security maintenance for the original, officially released versions of its products. If a product has been modified by a user or a third party without authorization, including but not limited to decompilation, flashing of third-party firmware, or modification of the system kernel, Delta may:
Deny Remediation: Not be responsible for remediating security vulnerabilities caused or expanded by such modifications.
Disclaim Liability: Assumes no legal or compensation liability for cyberattacks, data breaches, system outages, or similar incidents resulting from such modifications.
Suspend Updates: Reserve the right to suspend subsequent security update activities if abnormal modifications are detected in the product.
This Policy may contain links to third-party websites or resources. Delta assumes no responsibility for the content or accuracy of such third-party websites, or for their privacy policies or security measures.