The Unicore Product Security Incident Response Team (PSIRT) is a dedicated team responsible for the receipt, verification, and disclosure of vulnerabilities related to Unicore Communications products. Unicore Communications defines vulnerabilities as exploitable security issues in products that, when leveraged by attackers, could compromise the integrity, availability, or confidentiality of the product.
Vulnerabilities are not equivalent to quality defects. A quality defect is triggered without attacker involvement when its triggering conditions are met, whereas a vulnerability must be exploited by an attacker to be triggered. Unicore Communications encourages security researchers, industry organizations, customers, and suppliers to report suspected vulnerabilities related to Unicore Communications products to the Unicore PSIRT. The Unicore PSIRT will handle suspected product vulnerabilities in accordance with industry standards such as ISO/IEC 30111 and ISO/IEC 29147.
If you encounter or discover a suspected vulnerability in a product, you are welcome to notify the Unicore PSIRT in a timely manner. Please refer to the vulnerability reporting channel and security mechanism to submit suspected vulnerabilities. Vulnerability reporters may submit potential security vulnerabilities to Unicore via email at psirt@unicorecomm.com
[Download link for the Vulnerability Reporting Template to be added]
The continuous communication methods are shown in the table below:
| Stakeholder | Routine Communication Actions | Fixed Communication Timeline |
| Vulnerability Reporter / Individual | Establish a dedicated one-on-one communication mechanism covering the full lifecycle from acceptance, verification and classification, remediation planning, patch development, testing and acceptance to final public disclosure. Provide timely responses to the reporter’s questions, remediation inquiries, and disclosure requests. In cases of delayed disclosure, schedule adjustments, or plan changes, proactively inform the reporter with reasons and the latest action plan. | Acknowledgment within 3 business days of acceptance; progress updates every 7 business days for routine vulnerabilities; every 3 business days for high-risk vulnerabilities; final feedback within 3 business days after closure. |
| End Users | Establish a routine notification mechanism for all end users. For confirmed product security vulnerabilities, risks, and security update/patch solutions, notify users through official website announcements, user center, app push notifications, and after-sales notifications. Provide standardized Q&A for user inquiries, along with security protection and upgrade guidance, to reduce device risk. | Risk notification promptly after vulnerability classification is confirmed; company-wide notification completed within 3 business days after security update release. |
After receiving a vulnerability report, the PSIRT conducts an initial screening for information completeness. For reports that lack key information to support verification and classification, a standardized supplementary inquiry process is initiated, which specifies the inquiry content, timelines, and archival mechanisms to ensure efficient and precise vulnerability verification.
| Control Dimension | Core Implementation Standards | |
| Information Initial Screening Criteria | Complete the initial screening within 3 business days of receiving a vulnerability report. If any of the following conditions exist — missing product model/firmware version, no valid reproduction steps, no trigger scenario, no risk impact description, or no supporting evidence — immediately initiate the information supplementation inquiry process to avoid verification delays or risk misjudgment caused by incomplete information. | |
| Standardized Inquiry Content | Use a fixed template to request all critical information at once to avoid repeated communication. Core items include: applicable product model, software/hardware version, and production batch; complete reproduction steps, trigger conditions, and runtime environment; vulnerability anomaly description, impact on permissions, data, and device functions; remote exploitability, attack threshold, and batch impact scope; supporting evidence such as logs, screenshots, PoC, or videos; reporter contact information and privacy disclosure preference. | |
Inquiry Timeline & Communication Standards | If information is incomplete, initiate a formal inquiry through the original reporting channel within 3 business days, specifying the necessity of supplementation and the estimated verification timeline. Routine vulnerability supplementation deadline: 7 business days; high-risk vulnerability: 3 business days. Send reminders every 3 business days for overdue responses; after 2 cumulative non-responses, temporarily archive as a pending verification vulnerability, and restart the verification process once information is supplemented | |
| Information Consolidation & Fallback Mechanism | All supplementary information, communication records, and receipts are uniformly archived with screenshots and logged into the vulnerability information registry. For ambiguous or non-standard reports, PSIRT performs manual review and standardized organization to ensure complete and accurate vulnerability information, providing a reliable basis for subsequent reproduction, classification, and remediation, thereby preventing missed or erroneous judgments. | |
You will typically receive an email confirmation from the Unicore PSIRT within 3 business days, and will be informed of the progress of the issue as appropriate.
Timely awareness of vulnerabilities is an important prerequisite for prompt response. On one hand, Unicore encourages security researchers, industry organizations, customers, and suppliers to proactively report suspected vulnerabilities to the PSIRT, and requires upstream suppliers to promptly report vulnerabilities in deliverables to the company. On the other hand, Unicore proactively monitors well-known public vulnerability databases, open-source communities, security websites, and other information sources to promptly detect vulnerability information related to its products. We manage all detected suspected vulnerabilities and verify the affected status across all product versions.
Security Mechanism
Given the sensitivity of vulnerability information, to ensure confidentiality, we recommend that you use PGP (Pretty Good Privacy) to encrypt information sent to psirt@unicorecomm.com. Our PGP public key (Key ID: ......; PGP Fingerprint: ......) can be obtained by clicking here.
Throughout the vulnerability handling process, the Unicore PSIRT will strictly control the scope of vulnerability information, limiting communication to only those personnel involved in handling the vulnerability. We also request that reporters keep vulnerability information confidential until our customers have received a complete solution.
Vulnerability Handling
The PSIRT handles reported potential vulnerabilities in accordance with the vulnerability handling process.
Unicore is committed to enhancing product security and fully supporting the secure operation of customer networks and businesses. We emphasize vulnerability management in product development and maintenance, and have established a comprehensive vulnerability handling process in compliance with standards such as ISO/IEC 30111 and ISO/IEC 29147, to improve product security and ensure timely response when vulnerabilities are discovered.
1.Vulnerability Awareness: Accept and collect suspected vulnerabilities for products;
2.Verification & Assessment: Confirm the validity and impact scope of suspected vulnerabilities;
3.Vulnerability Remediation: Develop and implement vulnerability remediation plans;
4.Remediation Information Release: Publish vulnerability remediation information to customers;
5.Closure & Improvement: Continuously improve based on customer feedback and practical experience.
Vulnerability Severity Assessment
Unicore uses industry-standard criteria to assess the severity of suspected vulnerabilities in products. Taking CVSS (Common Vulnerability Scoring System) as an example, this model comprises three metric groups: Base Metric Group, Temporal Metric Group, and Environmental Metric Group. Unicore will provide the Base vulnerability score, and in certain cases, will also provide the Temporal vulnerability score and the Environmental vulnerability score for typical scenarios.
| Vulnerability Risk Level | Risk Scenario Description | |
| Critical / High-Risk Vulnerability | Vulnerabilities that can be remotely exploited, directly affect user personal/information safety, and carry the risk of large-scale exposure and attack. | |
| Medium-Risk Vulnerability | Vulnerabilities with partial functional safety impact, limited attack scenarios, and no potential for large-scale harm. | |
| Low-Risk Vulnerability | Vulnerabilities with no viable exploitation scenario, minimal harmful impact, and no effect on core product security or user operations. | |
General Control Requirements | Applicable to vulnerabilities of all severity levels. | |
Publishing Vulnerability Information
Version/patch release notes will include information on remediated vulnerabilities. As part of the product version/patch delivery package, these notes describe vulnerabilities of different severity levels. To facilitate comprehensive vulnerability risk assessment from the version/patch perspective by customers, the version/patch release notes also include vulnerability information and remediation plans previously published through security advisories. For private cloud scenarios, this information is included in the version documentation of cloud service products. For end-user device scenarios, this information is included in routine patch announcements.