Overview
ASIX is committed to maintaining the security, reliability, and integrity of its products throughout their supported lifecycle. Our Product Security Incident Response Team (PSIRT) coordinates the assessment, remediation, and disclosure of potential vulnerabilities affecting ASIX products and related software. ASIX considers applicable cybersecurity and regulatory requirements, including the European Union Cyber Resilience Act (EU CRA), as part of its product security practices. We encourage responsible vulnerability reporting from researchers, customers, partners, and the broader security community.
Report a Product Security Vulnerability
If you believe you have identified a potential security vulnerability affecting an ASIX product, firmware, driver, utility, software component, or related technology, please report it to the ASIX PSIRT at psirt@asix.com.tw. ASIX will review submitted reports, assess their security relevance and impact, investigate validated issues, and coordinate appropriate remediation and disclosure activities with relevant internal teams and stakeholders.
Vulnerability Report Information
When submitting a vulnerability report, please provide as much of the following information as possible:
- Details of the affected ASIX product, including the ASIX part number, hardware or chip revision, or product category
- Relevant ASIX firmware, driver, or software version(s)
- A clear description of the vulnerability, including the expected behavior, observed behavior, and potential security impact
- Details of the test environment, operating system, and relevant system configuration
- Detailed steps to reproduce the issue
- Proof-of-concept (PoC) code or other information that may help demonstrate or reproduce the vulnerability, if available
- Supporting materials, such as system logs, crash dumps, packet captures, screenshots, or videos; please provide these as separate attachments where possible
- References to related publicly known vulnerabilities, such as CVE identifiers, or security advisories, if applicable
- Information on whether the vulnerability has been disclosed to other organizations or discussed publicly
Please complete the ASIX Product Security Vulnerability Report Form and submit it, along with any supporting material files, to ASIX PSIRT: psirt@asix.com.tw
For reports containing sensitive technical information, we recommend using encrypted communication. The ASIX PGP (Pretty Good Privacy) public key is available at the link below.
File name: ASIX_PSIRT_PGP_Public_Key_20260824.zip (MD5: cc5423d493e000e906072c7b6404e9dc)
Security Vulnerability Bulletins
ASIX Product Security Vulnerability Bulletins provide information about confirmed vulnerabilities affecting ASIX products and related software components. Bulletins may include affected products and versions, severity assessments, available fixes or mitigations, and recommended actions to help customers and partners assess potential security risks and take appropriate protective measures. Where appropriate, ASIX may also acknowledge security researchers who responsibly report validated vulnerabilities, unless they prefer to remain anonymous.
ASIX Product Security Vulnerability Bulletins :
The detailed CVE Security Vulnerability Report can be downloaded from the Relaed Links at the bottom of this page.
- No bulletin is currently available.
Guidelines for Vulnerability Reporting
When conducting security research or submitting a vulnerability report to ASIX, please follow these guidelines:
- Report issues that relate to ASIX products, firmware, drivers, utilities, software, or other product-related technologies.
- Provide sufficient technical information to help ASIX understand, reproduce, and evaluate the issue.
- Allow ASIX reasonable time to investigate and address the vulnerability before public disclosure.
- Keep sensitive vulnerability information confidential while investigation and remediation activities are in progress.
- Conduct testing only on products, systems, or environments for which you have proper authorization.
- Avoid privacy violations, service disruption, data loss, or unauthorized access or modification.
- Ensure all testing and research activities comply with applicable laws and regulations.
Additional requirements may apply depending on applicable law, contractual obligations, or the circumstances of a specific report. ASIX reserves the right to determine whether a submitted issue qualifies as a product security vulnerability under this policy.
Vulnerability Response and Remediation Process
Upon receiving a vulnerability report, ASIX will make reasonable efforts to:
- Acknowledge receipt within approximately 3–5 business days
- Review submitted information and request additional technical details if needed
- Reproduce, investigate, and validate the reported issue
- Identify affected products, hardware or silicon revisions, firmware, drivers, or software versions
- Assess technical severity and potential security impact
- Coordinate with relevant product, design, firmware, software, quality, and other internal teams
- Maintain appropriate communication with the reporter throughout investigation and remediation
- Develop fixes, mitigations, workarounds, or security guidance where feasible
- Communicate with affected customers, OEM/ODM partners, distributors, and other stakeholders as necessary
- Publish a Product Security Vulnerability Bulletin when public disclosure is appropriate
ASIX aims to address confirmed vulnerabilities in a timely and coordinated manner. Where feasible, we generally target appropriate remediation, mitigation guidance, or stakeholder communication within approximately 90 days of validation. Actual timelines may vary depending on severity, technical complexity, product dependencies, testing requirements, customer qualification needs, product lifecycle status, and the availability of an effective remediation.
Vulnerability Severity Assessment
ASIX evaluates confirmed security vulnerabilities using recognized industry practices and may use the Common Vulnerability Scoring System (CVSS) as a reference. Final severity ratings may also consider product- and deployment-specific factors such as exploitability, attack complexity, exposed interfaces, system dependencies, customer impact, available mitigations, and evidence of actual exploitation. Where CVSS does not fully reflect the characteristics of embedded or semiconductor products, ASIX may apply additional product-specific considerations.
Regulatory Security Notifications
ASIX reviews confirmed product vulnerabilities and security incidents to determine whether regulatory reporting obligations apply. Where required by applicable laws, including the European Union Cyber Resilience Act (EU CRA), ASIX will submit the necessary notifications through the designated regulatory channels. This process is separate from the vulnerability reporting process on this page and does not change how researchers, customers, or partners should report issues to ASIX PSIRT.
Disclosure Policy
ASIX supports responsible and coordinated disclosure of security vulnerabilities affecting its products and related technologies. This policy outlines expectations for vulnerability reporting, investigation, remediation, and disclosure. Reporters are encouraged to provide sufficient technical information, keep sensitive details confidential during the investigation, and allow reasonable time for remediation before public disclosure. ASIX will make reasonable efforts to assess valid reports, maintain appropriate communication, and coordinate disclosure responsibly.
Disclaimer
ASIX may update this Product Security Vulnerability Disclosure Policy and related vulnerability handling processes as needed. Submission of a vulnerability report does not create a contractual relationship between ASIX and the reporter. ASIX reserves the right to determine the validity, severity, scope, remediation, communication, and disclosure of reported vulnerabilities in accordance with applicable legal and regulatory requirements. For information about personal data and privacy, please refer to the ASIX Privacy Policy .
FAQ
Q: How quickly will ASIX respond to a security vulnerability report?
A: ASIX strives to acknowledge receipt of an initial report within approximately 3 to 5 business days. The timelines for investigation, validation, and remediation depend on factors such as vulnerability severity, technical complexity, affected products and revisions, and the extent of required testing.
Q: How quickly will ASIX address a confirmed security vulnerability?
A: ASIX is committed to addressing confirmed vulnerabilities in a timely manner. Where feasible, we generally target remediation, mitigation guidance, or stakeholder communication within approximately 90 days of validation. Some issues may require additional time due to hardware dependencies, firmware or software changes, regression testing, downstream system integration, customer qualification, or other technical considerations.
Q: Will I be required to sign a Non Disclosure Agreement (NDA)?
A: No. An NDA is not typically required for submitting an initial vulnerability report. If the investigation involves confidential, proprietary, customer specific, or pre release product information, additional confidentiality arrangements may be discussed as appropriate.
Q: Can I submit a security vulnerability report anonymously?
A: Yes. You are not required to provide your name, organization, or other personal information. However, we recommend including a valid email address or other contact method so ASIX can request additional technical details and keep you informed about the investigation.
Q: How does ASIX assess vulnerability severity?
A: ASIX may use the Common Vulnerability Scoring System (CVSS) as a reference framework and supplement it with product specific considerations such as exploitability, affected interfaces, deployment environment, hardware or firmware dependencies, available mitigations, and potential customer impact.
Q: Can I submit an encrypted vulnerability report?
A: Yes. If your report contains sensitive technical information, ASIX recommends using encrypted communication. Please use the ASIX PGP Public Key to encrypt your report and send it to: psirt@asix.com.tw
Q: How will I know whether a vulnerability affects my ASIX product?
A: When public disclosure is appropriate, ASIX may publish a Product Security Vulnerability Bulletin identifying affected products or versions, available remediation or mitigation measures, and recommended customer actions. Customers should also review product documentation and security communications for information relevant to their deployed products.