Society

Vulnerability Disclosure Policy

To protect customers from cyberattacks involving the products and services we provide (hereinafter, “products”), Murata collects vulnerability information, assesses and responds to vulnerabilities, and discloses vulnerability information.

  1. Collection of vulnerability information

    Murata collects vulnerability information relating to its products from sources such as vulnerability databases and reports from finders outside the company.
    We accept information on vulnerabilities affecting Murata’s products. To submit such information, please use the vulnerability report form below.
    To help us investigate promptly, please include as much of the following information as possible in your report.

    • Name of the affected product or service (model name, part number, etc.) and version information
    • Where the issue occurs, steps to reproduce it, and the test environment
    • Your contact details (name / organization / email address)

    As a general rule, Murata will send a confirmation of receipt within seven business days for vulnerability reports received via the report form or other channels. We may also ask the reporter to provide additional information.

  2. Assessment of and response to vulnerabilities

    Murata investigates the impact of, and assesses the risk posed by, each vulnerability it identifies. Where the assessment indicates that action is required, we will address the vulnerability and disclose the relevant information.
    Murata also strives to maintain ongoing communication with reporters, coordinating organizations such as JPCERT/CC, customers, and other stakeholders, sharing information as appropriate in line with the progress of our investigation and response.

  3. Disclosure of vulnerability information

    Murata discloses information on its response to vulnerabilities in the products it provides (the affected products, the scope of impact, the severity, and the countermeasures) on our website.
    Where we determine that a vulnerability in one of our products may affect particular customers, we may instead make the disclosure by contacting those customers individually through our sales offices or other channels.

When an individual has contributed to the discovery or resolution of a vulnerability in a product provided by Murata, we will publish an acknowledgment of that contribution when we disclose the relevant vulnerability information, subject to the individual’s consent to the publication of such acknowledgment.

Link: Vulnerability Report FormOpen in New Window

When you report information about a product security vulnerability, this form uses TLS (HTTPS) for encrypted communication.
The information you submit is protected in transit. Vulnerability information is handled appropriately in accordance with our coordinated vulnerability disclosure process.

Link: Vulnerability Information List