Collection of vulnerability information
Murata collects vulnerability information relating to its products from sources such as vulnerability databases and reports from finders outside the company.
We accept information on vulnerabilities affecting Murata’s products. To submit such information, please use the vulnerability report form below.
To help us investigate promptly, please include as much of the following information as possible in your report.
- Name of the affected product or service (model name, part number, etc.) and version information
- Where the issue occurs, steps to reproduce it, and the test environment
- Your contact details (name / organization / email address)
As a general rule, Murata will send a confirmation of receipt within seven business days for vulnerability reports received via the report form or other channels. We may also ask the reporter to provide additional information.
Assessment of and response to vulnerabilities
Murata investigates the impact of, and assesses the risk posed by, each vulnerability it identifies. Where the assessment indicates that action is required, we will address the vulnerability and disclose the relevant information.
Murata also strives to maintain ongoing communication with reporters, coordinating organizations such as JPCERT/CC, customers, and other stakeholders, sharing information as appropriate in line with the progress of our investigation and response.
Disclosure of vulnerability information
Murata discloses information on its response to vulnerabilities in the products it provides (the affected products, the scope of impact, the severity, and the countermeasures) on our website.
Where we determine that a vulnerability in one of our products may affect particular customers, we may instead make the disclosure by contacting those customers individually through our sales offices or other channels.