Product Security  /  Vulnerability Disclosure

Report a security vulnerability

⚠️ Not all required fields are filled out.

Please go back to the form and try again.

If you've found a security issue affecting a Movacolor product, tell us about it here. Report only what you've observed — we'll follow up if we need more detail. Every question has a small (?) button next to it with an explanation and example, if you're unsure how to answer.

Acknowledged within
5 business days
Handled under
General terms for Vulnerability Disclosure
Report status
Confidential

Your contact details

Please enter your name.

Example: Jane Doe

This will be our main way of communicating with you about this report — updates, questions, and the outcome. Depending on the case, we may also be required to keep you informed as part of our regulatory reporting obligations, so we need a working address.

Example: jane.doe@company.com

Helps us understand the context — e.g. customer, integrator, or independent researcher.

Example: Acme Plastics BV

Used for regulatory and contact purposes only.

Example: Netherlands

Optional — only used if we need to reach you urgently.

Example: +31 6 1234 5678

Include country code.

Product affected

The Movacolor product line affected.

Found on the 'about screen' of your Movacolor controller.

Example: 3.11.1

Found on the 'about screen' of your Movacolor controller.

Required for PTC and MovaLink — optional for other products.

Found on the 'about screen' of your Movacolor controller.

Required for PTC and MovaLink — optional for other products.

Helps us confirm the exact unit configuration, if needed. you can find this on the type plate on your controller.

Example: 45445

If available — usually found on the unit's type plate.

What did you find?

What the issue is, and what it could allow someone to do.

Example: "The web interface accepts settings changes without checking who's logged in, so anyone on the network can change them."

Please describe step by step so we can see the same behavior on our side.

Example: "1. Connect to the unit's IP on port 80. 2. Send a POST request to /api/settings without a login token. 3. Settings change without authentication."

Please enter the date and time when you noticed the vulnerability for the first time

Example: 14 March 2026, 10:30, CET

Tells us whether this is isolated or wider-reaching.

Example: If you found this on one machine at one factory, choose "One."

Add the site name and country for each affected location.

Add every affected site. You can add as many as needed.

This helps us work out whether the issue needs to be reported to the authorities under the rules we follow. Every report is looked at by Movacolor regardless of your answer here — this question just helps us handle it correctly from the start.

Example: Logs showing repeated unauthorized access attempts that succeeded.

Screenshots, logs, or packet captures help us verify and reproduce the issue faster.

Example: A screenshot of the settings changing without a login prompt.

Attach files.

This helps us route your report correctly and, if needed, meet our reporting obligations to the authorities on time. Every report is reviewed by Movacolor either way — this just tells us which process to start with.

Example: If your production line stopped unexpectedly because of this issue, that's an incident. If you found a flaw during testing that hasn't caused real-world effects, that's a vulnerability.

Scope and impact

Answer to the best of your knowledge — "Unknown" is a valid answer.

A quick screening question — could an operator be locked out of the product or a key function?

Example: The touchscreen freezes and can't be used until the unit is rebooted.

Tells us whether the product could be made to do something it wasn't designed to do.

Example: Someone sends a command that makes the unit run a script it shouldn't.

We mean whichever network or systems this product is connected to. If you operate the equipment yourself, that's your own network. If you're reporting this on behalf of someone else — for example, as a distributor, integrator, or reseller — it means their network.

Example: The vulnerability lets someone move from the unit onto the wider factory network it's connected to.

How serious this is depends on two things: how sensitive the information is, and how many people could have seen it.

Example: A device's serial number becoming visible to another customer = Low. Material information becoming publicly downloadable = High.

Did the vulnerability expose or potentially expose sensitive data? Select all that apply.

Select every category of data that could have been seen.

Example: Recipes, mixture settings, or the unit's equipment type count as Configuration data. A customer's name and address would count as Personal data.

How badly could product or process quality be affected?

Example: A setting needing to be re-entered after a reset = Low. A wrong dosing ratio that wastes material and produces an out-of-spec batch = High.

How long, and how often, could the product be unusable?

Example: A quick reboot fixes it in a few minutes = Low. The unit is down for two hours and needs a remote support = High.

The worst thing that could realistically happen to a person's safety, or to the equipment.

Example: A small injury from touching moving parts, such as dosing screws with no effect on how the equipment works = Low. An unexpected motor start during maintenance that could cause a serious injury = High.

How exploitable is it?

If you're not certain, give your best estimate or choose "Unknown."

This tells us how someone would need to get to the affected part of the product — for example, whether they'd need to be physically standing at the machine, or could reach it over the internet.

Example: Needing someone to be physically present at the machine = Physical. Reachable from the wider factory network where IT and OT systems connect = Adjacent.

This is about how often someone would realistically get the chance — separate from how hard it would actually be to do.

Example: Only reachable during occasional, tightly controlled maintenance visits = Restricted. Reachable by multiple people as part of normal daily operations = Broadly Available.

The less skill it takes, the more people could potentially do this.

Example: Needing deep, specialist knowledge of this exact equipment = Expert. Just needing a web browser and basic tools = Basic.

Anything else?

Optional — anything not covered above that you think we should know.

Fields marked * are required.

Report received

Thank you — our product security team will acknowledge your report within 5 business days at the email address you provided.