Diese Website verwendet Browser-Cookies, um Ihnen das bestmögliche Nutzungserlebnis zu bieten. Die von uns verwendeten Cookies umfassen auch Cookies von Drittanbietern.
Weitere Informationen finden Sie in unserer [Datenschutz- und Cookie-Richtlinie].
Durch das Klicken auf „Akzeptieren“ stimmen Sie der aktuellen Verwendung unserer Cookies zu. Alternativ können Sie Ihre Cookie-Einstellungen individuell verwalten.
Latest Security Updates
Please refer to link : Security & Technical Advisory - GIGABYTE Global
GIGAIPC Coordinated Vulnerability Disclosure Policy
Version: 1.0
Effective Date: September 1, 2026
Last Updated: September 1, 2026
GIGAIPC Co., Ltd. (“GIGAIPC”) is committed to the security of our products and services and to providing our customers with secure and reliable products.
We recognize the important role that security researchers, customers, partners, and the broader security community play in helping improve product security. GIGAIPC supports the principles of Coordinated Vulnerability Disclosure (CVD) and encourages the responsible, good-faith reporting of potential security vulnerabilities.
By working collaboratively with researchers, we aim to validate reported vulnerabilities, assess their potential impact, develop appropriate fixes or mitigations, and coordinate disclosure in a manner that helps protect customers and the broader ecosystem.
1. Scope
This Policy applies to GIGAIPC-branded products and related digital components that are provided or maintained by GIGAIPC Co., Ltd., including, but not limited to:
- GIGAIPC-branded hardware products;
- BIOS, UEFI, BMC, firmware, and other product firmware;
- drivers, utilities, and product-related software; and
- digital services provided by GIGAIPC that are directly related to product functionality or product security.
Where a reported vulnerability affects a third-party component, open-source software, chipset, firmware, or other supplier technology, GIGAIPC may coordinate with the relevant supplier, maintainer, or vulnerability coordination organization as appropriate.
Products, services, or systems operated by affiliates, other brands, or third parties, or that are not maintained by GIGAIPC Co., Ltd., may fall outside the scope of this Policy.
GIGAIPC may still accept vulnerability reports concerning products that have reached the end of their support lifecycle. However, investigation, remediation, or other actions for such products will be evaluated on a case-by-case basis.
2. Reporting a Security Vulnerability
If you believe you have identified a security vulnerability affecting a GIGAIPC product or service, please report it to the GIGAIPC Product Security Incident Response Team (PSIRT) through the following channels:
Security Contact: PSIRT@gigaipc.com
Security Advisory: https://www.gigaipc.com/security/vulnerability-disclosure-policy
Vulnerability Reporting: https://www.gigaipc.com/security/vulnerability-reporting
PGP Public Key: https://www.gigaipc.com/pgp-key.asc
Security Advisory: https://www.gigaipc.com/security/security-advisory
Security.txt: https://www.gigaipc.com/.well-known/security.txt
If your report contains sensitive technical information, proof-of-concept code, credentials, personal data, or other confidential information, we recommend encrypting the report using GIGAIPC's published PGP Public Key.
Please refer to the GIGAIPC website or our security.txt file for the latest product security contact and encryption information.
3. Information to Include in Your Report
To help us investigate and respond efficiently, please provide as much of the following information as possible:
- the affected product name and model;
- the affected BIOS, firmware, driver, software, or other relevant version;
- a clear technical description of the vulnerability and its potential security impact;
- the environment, conditions, and detailed steps required to reproduce the issue;
- proof-of-concept (PoC) code or other supporting technical information, where applicable;
- known attack scenarios or conditions required for exploitation;
- whether you are aware of the vulnerability being actively exploited;
- whether the vulnerability has also been reported to another vendor, CNA, CERT/CSIRT, or other coordination organization;
- any planned public disclosure date; and
- an email address or other contact information through which GIGAIPC may follow up with you.
You may submit a report using your legal name, researcher identity, alias, or other identifier.
Please note that if you do not provide contact information, our ability to request additional information or provide updates regarding the investigation may be limited.
Please do not submit passwords, private keys, personal data, or other sensitive information that is not reasonably necessary to validate the vulnerability through unencrypted channels.
4. Guidelines for Responsible Security Research
GIGAIPC appreciates the efforts of security researchers who help us improve the security of our products and services.
When conducting security research or validating a potential vulnerability, we ask that you:
- limit testing to what is reasonably necessary to demonstrate or validate the vulnerability;
- make reasonable efforts to avoid disrupting the normal operation of products, services, systems, or networks;
- do not access, download, modify, delete, destroy, or misuse data without authorization;
- do not conduct denial-of-service (DoS), distributed denial-of-service (DDoS), or other destructive testing;
- do not conduct social engineering or phishing against GIGAIPC employees, customers, or partners;
- do not install malware, establish persistent access, or retain access beyond what is reasonably necessary to validate the vulnerability;
- do not use a vulnerability for fraud, extortion, financial gain through improper means, or any other unlawful purpose;
- make reasonable efforts to avoid violating the privacy or rights of GIGAIPC, our customers, or third parties;
- allow GIGAIPC a reasonable opportunity to investigate, remediate, or mitigate the vulnerability before public disclosure; and
- coordinate with GIGAIPC before publicly disclosing technical information that could enable exploitation of the vulnerability.
All security research must comply with applicable laws and regulations.
5. Vulnerability Handling and Coordination Process
After receiving a vulnerability report, GIGAIPC PSIRT will evaluate and handle the report based on the nature and risk of the vulnerability. Where appropriate, GIGAIPC uses the Common Vulnerability Scoring System (CVSS) as part of its vulnerability severity assessment.
Acknowledgment
GIGAIPC will make reasonable efforts to acknowledge receipt of a valid product security vulnerability report within three business days.
If additional information is required to analyze or reproduce the reported issue, we may contact the reporter for further details.
If requested information is not provided within 30 days, GIGAIPC may close the report. A closed report may be reopened if sufficient information is subsequently provided.
Validation and Risk Assessment
As appropriate, GIGAIPC PSIRT will work with relevant product, engineering, and security teams to:
- validate and reproduce the vulnerability;
- identify affected products and versions;
- assess potential security impact and exploitability;
- determine vulnerability severity;
- perform root-cause analysis; and
- evaluate the overall security risk.
Remediation and Mitigation
For confirmed vulnerabilities, GIGAIPC will determine appropriate actions based on the assessed risk and product circumstances.
Such actions may include:
- BIOS, firmware, driver, or software updates;
- security patches;
- configuration changes;
- workarounds or mitigations;
- security guidance for users; or
- coordinated remediation with third-party component suppliers.
Where a vulnerability involves third-party components or affects multiple vendors, GIGAIPC may coordinate with relevant suppliers, CVE Numbering Authorities (CNAs), CERTs/CSIRTs, or other appropriate vulnerability coordination organizations.
6. Coordinated Disclosure and Security Advisories
GIGAIPC will consider the severity of the vulnerability, affected products, remediation status, customer risk, and coordination requirements with relevant suppliers or other parties when determining an appropriate disclosure timeline.
To reduce the risk of exploitation before users have an opportunity to apply appropriate protections, we ask researchers not to publicly disclose detailed technical information or exploit code that could enable reproduction or exploitation of the vulnerability until the coordinated disclosure process has been completed.
When a confirmed vulnerability requires customer action, GIGAIPC may publish information through a GIGAIPC Security Advisory or other appropriate communication channels.
Depending on the circumstances, a Security Advisory may include:
- a CVE Identifier;
- a description of the vulnerability;
- affected products and versions;
- vulnerability severity and security impact;
- remediation or updated versions;
- workarounds or mitigation measures;
- recommended customer actions;
- publication and revision dates; and
- acknowledgment of the security researcher.
In certain circumstances, GIGAIPC may delay publication of specific technical details where immediate disclosure could materially increase the risk to customers before appropriate fixes or mitigations can be deployed.
7. Remediation Timelines and Communication
The time required to validate, assess, and remediate a vulnerability may vary depending on factors such as:
- vulnerability complexity and severity;
- the number of affected products and versions;
- differences in hardware, firmware, and software architectures;
- development, validation, compatibility, and quality testing requirements;
- dependencies on third-party components or suppliers;
- CVE coordination or multi-vendor coordinated disclosure; and
- embargoes or other vulnerability disclosure arrangements.
Accordingly, except where expressly stated otherwise in this Policy, GIGAIPC does not commit to a fixed remediation timeline for any specific vulnerability.
During the investigation, GIGAIPC will make reasonable efforts, where appropriate and practicable, to communicate material case updates to the reporter.
8. Safe Harbor for Good-Faith Security Research
GIGAIPC supports good-faith security research intended to improve the security of our products and services.
To the extent permitted by applicable law, GIGAIPC will not initiate legal action solely on the basis of security research conducted in good faith and in accordance with this Policy, provided that the researcher:
- acts in good faith for legitimate security research purposes;
- complies with the guidelines set out in this Policy;
- limits testing to what is reasonably necessary to validate the vulnerability;
- takes reasonable measures to avoid harm to GIGAIPC, our customers, or third parties; and
- reports the vulnerability to GIGAIPC in accordance with this Policy and participates in reasonable coordinated disclosure efforts.
This Safe Harbor does not apply to:
- malicious, fraudulent, extortionate, or otherwise unlawful activity;
- intentional damage to products, systems, services, or data;
- unauthorized acquisition, use, or disclosure of data;
- DoS, DDoS, or other activities that impair service availability;
- social engineering or phishing; or
- activities that clearly exceed what is reasonably necessary for legitimate security research or vulnerability validation.
This Policy applies only to products and systems that GIGAIPC has the authority to manage or authorize for testing.
GIGAIPC cannot authorize security research involving products, services, systems, networks, or infrastructure owned, operated, or controlled by third parties.
9. CVE Assignment, Researcher Recognition, and Rewards
Depending on the nature of the vulnerability and the circumstances of the case, GIGAIPC may obtain a CVE Identifier directly or in coordination with an appropriate CVE Numbering Authority (CNA) or vulnerability coordination organization.
With the reporter's consent and where GIGAIPC considers it appropriate, we may publicly acknowledge the security researcher or organization in the relevant Security Advisory.
Researchers may also choose to remain anonymous or use a preferred researcher identity.
Unless GIGAIPC has separately announced an official Bug Bounty Program or other security research reward program, this Policy does not constitute a commitment to provide any monetary reward, compensation, or other payment for vulnerability reports.
10. Privacy and Use of Information
Contact information and other information submitted to GIGAIPC in connection with a vulnerability report will be used primarily for purposes including:
- vulnerability validation and technical analysis;
- communicating with the reporter;
- remediation and security risk management;
- coordinated vulnerability disclosure;
- security advisories and related coordination; and
- compliance with applicable legal and regulatory requirements.
GIGAIPC will handle such information in accordance with applicable data protection, privacy, and information security requirements.
11. Disclaimer
This Policy describes GIGAIPC's general approach and procedures for coordinated vulnerability disclosure and product security vulnerability handling.
It does not create any express or implied warranty, contractual obligation, service level agreement (SLA), or commitment to a specific outcome.
The time required to validate, assess, remediate, and disclose a vulnerability may vary depending on the complexity of the vulnerability, affected products, third-party dependencies, supplier coordination, validation and testing requirements, embargo arrangements, and other relevant circumstances.
GIGAIPC may update or adjust this Policy and its related processes as appropriate in response to security risks, product circumstances, industry practices, or applicable legal and regulatory requirements.
Nothing in this Policy authorizes unlawful, unauthorized, destructive, or otherwise harmful activity affecting GIGAIPC, our customers, third parties, or their respective systems, services, data, or rights.
Nothing in this Disclaimer is intended to exclude, restrict, or otherwise affect any obligation imposed on GIGAIPC under applicable mandatory laws or regulations.
12. Policy Updates and Contact Information
GIGAIPC may update this Policy from time to time in response to changes in our products, the threat landscape, industry practices, or applicable legal and regulatory requirements.
The current version of this Policy will be published on the official GIGAIPC website.