PSIRT & Security Advisories

Product Security Incident Response Team (PSIRT)

Vector’s Product Security Incident Response Team (PSIRT) is your first contact to report cybersecurity topics in connection with products, embedded products, and services developed by Vector.

This team analyzes any incoming information, initiates appropriate actions, and coordinates the response process to ensure vulnerabilities are handled efficiently and responsibly.

Reporting a Vulnerability

If you have identified a potential vulnerability or security issue, please use our PSIRT Support and Vulnerability Reporting form as the primary and preferred reporting channel.

Our preferred languages for communication are English and German.

Please provide the following information when submitting a vulnerability:

  • Affected product(s) or software version

  • Description of the vulnerability, including technical details, steps to reproduce as well as potential impact

  • If available, related documents concerning the reported vulnerability (CVE ID, announcements, etc.) 

Alternatively, you may contact us via e-mail at: psirt@vector.com

In order to take into account the high protection requirements of such topics, usage of encryption for communication is preferred. You can find Vector’s PSIRT PGP public keys and fingerprints here:

Public Key

4C3E A23D 3311 34D8 68D4 29C7 B70E DD48 C0ED 5B70

We kindly ask you not to publish or share with third parties any unresolved vulnerability in connection with Vector’s products.

Security Advisories

The Security Advisories from Vector are published to notify customers about critical security vulnerabilities and provide guidance on how to minimize and mitigate the risks associated with such vulnerabilities. We are aware of the following, please use the latest released advice (highest version):

VulnerabilityAdvisory IDAdvisory, released onVersionRemarks
WIBU CodeMeter Privilege EscalationLM-110422025-05-161.0no special remarks
WIBU CmDongle Security VulnerabilitiesLM-97892024-12-181.0no special remarks
WIBU Systems CodeMeter Runtime Vulnerabilities 2024-05-271.0no special remarks
Apache ActiveMQ (CVE-2023-46604) 2023-12-121.0no special remarks
Apache Log4j2 (CVE-2021-45046) Security Vulnerabilities see details page1.0no special remarks
Apache Log4j2 (CVE-2021-45105) Security Vulnerabilities see details page1.0no special remarks
Apache Log4j2 (CVE-2021-44228) Security Vulnerabilities see details page1.0no special remarks
WIBU Systems CodeMeter Runtime VulnerabilitiesLM-57082021-11-101.0no special remarks
WIBU Systems CodeMeter Runtime VulnerabilitiesLM-47102021-06-171.0no special remarks
WIBU Systems CodeMeter Runtime Vulnerabilities 2020-10-151.3no special remarks

Vector reserves the right to change or update this content without notice at any time to provide the latest available guidance.