PSIRT at Ericsson
Security is a top priority for Ericsson products and services in today’s rapidly evolving threat and vulnerability landscape. Ericsson PSIRT (Product Security Incident Response Team) is responsible for Ericsson product vulnerability management process, coordination of customer product security incidents and reported security issues affecting Ericsson products, solutions, and services.
This is Ericsson PSIRT
Modern telecom networks are a complex part of the critical infrastructure of our digital society. Security of the networks is essential for keeping critical services available and reliable. Unfortunately, seamlessly secure networks rarely exist, and security must be considered from the initial steps of product development until the end of the product’s life cycle and even further in the life cycle management processes.
Ensuring the security of software in the highly dynamic and ever-changing security landscape is a continuous and evolving process. PSIRT has a central role in this at Ericsson. We strongly believe in the principles of responsible vulnerability disclosure towards all parties involved.
PSIRT has two major operations: Vulnerability management and incident response. PSIRT also works closely with the internal Security Reliability Model (SRM) processes. That guarantees the seamless flow of product security related information between customer, support organization and product development.
Product Vulnerability Disclosures
Ericsson welcomes independent security researchers, vendors, customers, and other sources to responsibly report security vulnerabilities affecting the Ericsson product portfolio.
To see our product vulnerability disclosure policy, visit Ericsson product vulnerability disclosure policy page.
To report a potential security vulnerability in any Ericsson products or services, see our Vulnerability reporting form page.
Ericsson published Security Bulletins and Notices are available at Security bulletins page.
PSIRT and the security community
PSIRT was established in 2004 and was accredited by Trusted Introducer (GEANT/TF-CSIRT) in 2005. PSIRT actively contributes and collaborate with the wider cybersecurity community. Here are a few examples:
- Full member of FIRST, a global Forum of Incident Response and Security Teams, since 2006.
- Active in co-operation with international Computer Emergency Response Team (CERT) communities, vendors, and many telecom operator Computer Security Incident Response Team (CSIRT) teams.
- Works with the ETIS community of telecom professionals.
- Member in GSMA’s industry Coordinated Vulnerability Disclosure Programme.
- Ericsson is a CVE Numbering Authority (CNA).
Contact PSIRT
E-mail: psirt@ericsson.com
PGP key fingerprint:
1A5E C39F C325 A701 48AC 924E D8F3 449D 034F 6945
Ericsson PSIRT PGP key (.txt)
Note: Please encrypt all of your messages with the PGP key and include your own public key for future correspondence.