PSIRT & Security Advisories
Product Security Incident Response Team (PSIRT)
Vector’s Product Security Incident Response Team (PSIRT) is your first contact to report cybersecurity topics in connection with products, embedded products, and services developed by Vector.
This team analyzes any incoming information, initiates appropriate actions, and coordinates the response process to ensure vulnerabilities are handled efficiently and responsibly.
Reporting a Vulnerability
If you have identified a potential vulnerability or security issue, please use our PSIRT Support and Vulnerability Reporting form as the primary and preferred reporting channel.
Our preferred languages for communication are English and German.
Please provide the following information when submitting a vulnerability:
Affected product(s) or software version
Description of the vulnerability, including technical details, steps to reproduce as well as potential impact
If available, related documents concerning the reported vulnerability (CVE ID, announcements, etc.)
Alternatively, you may contact us via e-mail at: psirt@vector.com
In order to take into account the high protection requirements of such topics, usage of encryption for communication is preferred. You can find Vector’s PSIRT PGP public keys and fingerprints here:
4C3E A23D 3311 34D8 68D4 29C7 B70E DD48 C0ED 5B70
We kindly ask you not to publish or share with third parties any unresolved vulnerability in connection with Vector’s products.
Security Advisories
The Security Advisories from Vector are published to notify customers about critical security vulnerabilities and provide guidance on how to minimize and mitigate the risks associated with such vulnerabilities. We are aware of the following, please use the latest released advice (highest version):
| Vulnerability | Advisory ID | Advisory, released on | Version | Remarks |
| WIBU CodeMeter Privilege Escalation | LM-11042 | 2025-05-16 | 1.0 | no special remarks |
| WIBU CmDongle Security Vulnerabilities | LM-9789 | 2024-12-18 | 1.0 | no special remarks |
| WIBU Systems CodeMeter Runtime Vulnerabilities | 2024-05-27 | 1.0 | no special remarks | |
| Apache ActiveMQ (CVE-2023-46604) | 2023-12-12 | 1.0 | no special remarks | |
| Apache Log4j2 (CVE-2021-45046) Security Vulnerabilities | see details page | 1.0 | no special remarks | |
| Apache Log4j2 (CVE-2021-45105) Security Vulnerabilities | see details page | 1.0 | no special remarks | |
| Apache Log4j2 (CVE-2021-44228) Security Vulnerabilities | see details page | 1.0 | no special remarks | |
| WIBU Systems CodeMeter Runtime Vulnerabilities | LM-5708 | 2021-11-10 | 1.0 | no special remarks |
| WIBU Systems CodeMeter Runtime Vulnerabilities | LM-4710 | 2021-06-17 | 1.0 | no special remarks |
| WIBU Systems CodeMeter Runtime Vulnerabilities | 2020-10-15 | 1.3 | no special remarks |
Vector reserves the right to change or update this content without notice at any time to provide the latest available guidance.