Coordinated Vulnerability Disclosure (CVD) Policy
Introduction and Commitment
BODET TIME & SPORT is committed to processing vulnerability reports in a structured, confidential, and risk-proportionate manner, and to taking appropriate corrective or mitigating measures in accordance with applicable regulatory requirements.
This policy is part of BODET TIME & SPORT's global vulnerability handling process and complements its internal procedures for triage ans assessment, remediation, regulatory notification, and security update management.
Scope
This policy applies to BODET TIME & SPORT products during the security support period defined for the product, covering a period of 5 years (extended to a maximum of 10 years) from its market placement, as well as third-party components integrated into these products.
Vulnerabilities may be identified by external researchers, customers, partners, suppliers, BODET TIME & SPORT teams, or through security monitoring and testing activities.
Each report is recorded and tracked to monitor its triage and assessment remediation actions, and, where applicable, associated communications.
How to report a vulnerability
If you discover a vulnerability in one of our products, you can inform us via our dedicated contact point: Report a vulnerability.
Accepted languages: French, English
Our commitment and processing times
To ensure transparent and constructive collaboration, we commit to the following milestones:
- Acknowledgment of receipt: Within 2 business days maximum
- Initial assessment and feedback to reporter: Within 5 business days
- Triage and assessment: Depending on the criticality and complexity of the report, by BODET teams
- Remediation: Prioritized according to risk
- Communication: Depending on criticality and the need for coordination with third parties
These timeframes are CVD processing targets and do not prejudge the applicable regulatory deadlines for mandatory notifications, which BODET TIME & SPORT complies with.
Actively exploited vulnerabilities
When a vulnerability affecting a BODET TIME & SPORT product is identified as being actively exploited, or when there is reasonable evidence that it is subject to active exploitation, BODET TIME & SPORT triggers its vulnerability management process and, where regulatory conditions are met, notification procedures under the Cyber Resilience Act.
Information indicating active exploitation must be communicated to BODET TIME & SPORT as soon as possible.
Affected users are informed of the risks and of the corrective or mitigating measures to be implemented.
Safe Harbor
BODET TIME & SPORT will not seek to bring legal action against a researcher/reporter who, in good faith and in compliance with this policy, conducts research activities aimed at identifying and reporting a vulnerability.
This commitment does not apply to intentionally malicious or fraudulent activities, violations of applicable law, or actions causing disproportionate damage to third-party systems, products, or data.
Coordinated Disclosure
The researcher is requested not to publicly disclose detailed technical information relating to the vulnerability during the coordination phase, in order to allow BODET TIME & SPORT to analyze the issue, prepare corrective measures, and inform users.
The disclosure terms and timeline are, as far as possible, agreed with the researcher, taking into account risk, availability of corrective measures, and applicable regulatory obligations.
Security advisories
When a vulnerability requires public communication, BODET TIME & SPORT publishes a Security Advisory containing, where relevant:
- the vulnerability identifier
- the affected product and versions
- the fixed or remediated versions
- a description of the vulnerability
- its impact
- its severity level
- the CVSS score, when available
- the CVE number, when assigned or applicable
- corrective or mitigating measures
- instructions enabling users to reduce or eliminate the risk
This communication is published in the TIME CONNECT area.
When a vulnerability affects a third-party component integrated into a BODET Time product, BODET TIME & SPORT coordinates actions with the relevant vendor or publisher where necessary, evaluates the impact on affected BODET products, and implements appropriate corrective or mitigating measures.
Data protection
Personal information provided in connection with a report is processed in accordance with BODET TIME & SPORT's Privacy Policy and only to the extent necessary to process the report.
Vulnerability-related information is handled confidentially and is accessible only to persons who need to know it for analysis, remediation, or compliance with applicable regulatory obligations.
Policy limitations
This policy does not constitute a general authorization to conduct security testing on BODET TIME & SPORT’s products, systems or infrastructure, or on those of its customers.
Research activities must be conducted in compliance with this policy and with applicable laws and regulations and, where the equipment or system is not owned by the researcher, with the authorization of its owner.
This policy may be updated to reflect changes in products, security practices, and applicable regulatory requirements.