Sungrow Logo
Security Incident Response

Sungrow PSIRT

Security Incident Response

Sungrow places great importance on the remediation of security and privacy vulnerabilities. The Sungrow Product Security Incident Response Team (PSIRT) spearheads the company’s Vulnerability Disclosure Program (VDP), responsible for the intake, investigation, internal coordination, and disclosure of security vulnerability information associated with Sungrow’s products and services.

Overview

Sungrow is committed to maintaining the security of its products, services, and customers. We welcome security researchers, customers, partners, and other stakeholders to responsibly report potential security vulnerabilities that may affect Sungrow products, systems, or services.

By working collaboratively with the security community, we can identify, assess, and remediate security issues more effectively, helping to strengthen the overall security of our products and services.

Scope

This policy applies to all of Sungrow's products.

How to Report a Vulnerability

If you believe you have identified a security vulnerability affecting a Sungrow product or service, please submit your report through one of the following channels:

To protect the confidentiality of vulnerability information, we recommend using PGP encryption when submitting vulnerability reports.

Information to Include

To facilitate efficient analysis and validation, vulnerability reports should include as much of the following information as possible:

Affected product name and model

Software, firmware, or system version

Detailed description of the vulnerability

Vulnerability type (e.g., privilege escalation, remote code execution, authentication bypass)

Potential impact and risk assessment

Steps required to reproduce the vulnerability

Test environment information

Proof-of-Concept (PoC) code, scripts, logs, screenshots, or other supporting materials

Contact information (optional)

The more complete the information provided, the more efficiently we can evaluate and address the reported issue.

Response Commitment

Upon receiving a vulnerability report, Sungrow PSIRT team will begin analysis and validation as soon as possible.

Under normal circumstances:

Receipt of the report will be acknowledged within 1 business day;

Initial assessment and validation results will be provided within 7 business days;

Significant progress updates will be communicated throughout the remediation process.

Complex vulnerabilities, vulnerabilities affecting multiple products, or issues requiring coordination with third parties may require additional time for investigation and remediation.

Vulnerability Handling Process and Disclosure Principles

The vulnerability handling process typically includes:

Vulnerability receipt and confirmation;

Vulnerability verification and impact assessment;

Risk classification and remediation plan development;

Patch development, testing and validation;

Customer notifications and security advisories;

Public disclosure of vulnerabilities;

Closed-loop retrospective and continuous improvement.

Sungrow adheres to the principles of Coordinated Vulnerability Disclosure (CVD) in handling security vulnerabilities. In principle, vulnerability details will not be publicly disclosed until a vulnerability fix is available.


Sungrow typically discloses vulnerability information and remediation solutions to the public in two ways:
Security Advisory(SA):Provides information on the vulnerability severity level, the range of affected products and versions, business impact, and remediation measures. It is typically used to disclose information about critical and high-risk security vulnerabilities in Sungrow products, along with corresponding remediation plans, so that customers can be informed of these vulnerabilities.Sungrow reserves the right to issue and continuously update vulnerability advisories.
Release Note(RN):Provides information on resolved vulnerabilities. It is used to disclose the security vulnerabilities that have been fixed during the development process, so that customers can understand the security status of the product.

If any of the following circumstances occur, Sungrow will release a Security Advisory (SA) to support customers in making informed decisions based on actual live network risks.
● For vulnerabilities classified as “Critical” or “High” in severity, Sungrow has completed its vulnerability response process and can provide remediation solutions to help customers mitigate risks in their live networks.
● If the vulnerabilities in Sungrow’s product versions are likely to attract widespread public attention, or if Sungrow has observed active exploitation of such vulnerabilities—potentially increasing the risks faced by its customers—Sungrow will expedite its response process. Within 24 hours of confirming that the aforementioned conditions are met, it will notify customers and provide ongoing updates on the status of the vulnerability response.

Safe Harbor

Sungrow supports good-faith, responsible security research activities.

Sungrow undertakes not to initiate legal proceedings or take any legal action against individuals who comply with this policy and conduct security research in good faith, provided that the relevant research activities meet the following conditions:

Do not cause any business disruption to customers, partners, or Sungrow.

Do not access, modify, delete, or disclose unauthorized data;

Do not conduct denial-of-service (DoS) attacks;

Do not exploit vulnerabilities to conduct lateral movement, establish persistent control, or launch further attacks.

Do not violate applicable laws and regulations;

Do not disclose vulnerability details publicly until the vulnerability has been patched.

Should research activities exceed the aforementioned scope, Sungrow reserves the right to take appropriate measures.

Recognition

Sungrow appreciates the valuable contributions of the security research community.

For valid and responsibly reported vulnerabilities, Sungrow may acknowledge the reporter's contribution. With the reporter's consent, recognition may be provided through security advisories, acknowledgments, or other appropriate channels.

Currently, Sungrow does not operate a public bug bounty program. Should such a program be introduced in the future, detailed information will be published on the official website.

Contact

For questions regarding this VDP or other product security matters, please contact Sungrow PSIRT:psirt@sungrowpower.com

Homeowners
Business Owners
Large Scale
Partners
Products
Service & Support
Sustainability
About Us
© 2023 SUNGROW. All Rights Reserved.
chatbotchatbot