Skip to content

Vulnerability Responsible
Disclosure Policy

INTRODUCTION AND PURPOSE:

The Infoblox Product Security Incident Response Team (“PSIRT”) is responsible for responding to Infoblox product security incidents. The Infoblox PSIRT is a global team that manages the receipt, investigation, and public reporting of information about security vulnerabilities and issues related to Infoblox products. Infoblox defines a security vulnerability as an unintended weakness in a product that could allow an attacker to compromise the integrity, availability, or confidentiality of a product or service.

Infoblox will engage with security researchers when vulnerabilities are reported to us in accordance with this Vulnerability Responsible Disclosure Policy (the “Policy”). We will validate and fix vulnerabilities in accordance with our commitment to security and privacy. We will not take legal action against or suspend or terminate accounts of those who discover and report security vulnerabilities in accordance with this Policy. Infoblox reserves all legal rights in the event of any noncompliance with this Policy.

For questions on this Policy, or to confirm your security research complies with it, contact PSIRT@infoblox.com or security-report@infoblox.com.

REPORTING:

Infoblox encourages security researchers to share the details of any suspected vulnerabilities with our Product Security team by sending an email to PSIRT@infoblox.com or security-report@infoblox.com. Infoblox will review the submission and take appropriate actions or measures to secure any confirmed vulnerability. Vulnerability Disclosure

CVE ID ASSIGNMENT AND COORDINATED DISCLOSURE:

Infoblox participates in the Common Vulnerabilities and Exposures (CVE) Program as a CVE Numbering Authority (CNA). Infoblox’s CNA scope covers eligible vulnerabilities in Infoblox products and services owned, developed or maintained by Infoblox, as defined in Infoblox’s approved CNA Scope Definition.

A vulnerability is an unintended weakness in an Infoblox product or service that can be exploited and cause a negative impact to confidentiality, integrity or availability, or allow an explicit or implicit security policy to be violated. Examples may include authentication or authorization bypass, privilege escalation, code execution, injection, sensitive information disclosure, cryptographic weaknesses and security-impacting insecure default configurations. Infoblox will determine whether a reported issue is a vulnerability, whether it is within CNA scope and whether it represents one or more vulnerabilities.

Issues that do not create a security impact generally will not be treated as vulnerabilities. The fact that a product is end of life, or that an issue involves physical access, brute-force denial of service or detection bypass, does not by itself establish a vulnerability. Infoblox will apply the CVE Program Rules and its judgment to unusual or borderline cases.

Third parties should report suspected vulnerabilities privately to PSIRT@infoblox.com, or security-report@infoblox.com., as described in the Reporting section. Reports should include the affected product and version, a vulnerability description, security impact, reproduction steps or proof of concept, relevant prerequisites and the reporter’s contact information. Reporters should also identify whether the issue has been reported to another CNA or publicly disclosed.

After receiving a report, Infoblox will acknowledge receipt, create an internal tracking record and assess whether the report is within scope, represents a vulnerability and is expected to be publicly disclosed. Infoblox will target an acknowledgment within three business days and an initial triage update within 10 business days.

When Infoblox has reasonable evidence that an in-scope vulnerability exists and the vulnerability is publicly disclosed or expected to be publicly disclosed, Infoblox will assign or reserve one or more CVE IDs, as appropriate, in accordance with the CVE Program Rules. Infoblox will provide the CVE ID or CVE IDs, as appropriate, to the reporter when available. Infoblox may request additional information and coordinate with other affected parties before finalizing the assignment.

Infoblox will not assign a CVE ID for a vulnerability outside its CNA scope. If another CNA has the more appropriate scope, Infoblox may refer the reporter to that CNA or coordinate with it.

Infoblox will coordinate remediation and public disclosure with the reporter and affected parties when applicable, in accordance with the CVE Program Rules. Infoblox may establish an embargo period while a fix or mitigation is developed. The reporter is expected to keep the report and related technical details confidential during an agreed embargo period, avoid further testing when requested and coordinate the public disclosure date and technical details with Infoblox.

Infoblox will publish a public security advisory or other vulnerability information that references the assigned CVE ID and will publish the corresponding CVE Record to the CVE List through the mechanisms designated by the CVE Program. Infoblox will target publication within 24 hours after public disclosure and will publish no later than 72 hours after public disclosure of an Infoblox-assigned CVE ID.

The CVE Record will not be the first public disclosure of a vulnerability. Infoblox will ensure that a public reference containing information about the specific vulnerability exists before or concurrently with publication of the CVE Record.

Before public disclosure, Infoblox may discuss the report’s status, affected products and versions, validation, remediation or mitigation progress, CVE assignment status and anticipated publication timing with the reporter and relevant affected parties. Infoblox will not normally disclose nonpublic technical details, reporter identity, customer information or exploit material without authorization from the relevant party, as applicable, unless required by law, necessary to protect customers or needed to comply with CVE Program Rules.

Infoblox may credit the reporter in its advisory or CVE Record when the reporter provides consent and a preferred form of credit. A reporter may request anonymity.

SAFE HARBOR:

In order to encourage security research into our products, Infoblox will not bring legal action against anyone who makes a good faith effort to report a known or suspected vulnerability in our products in compliance with this Policy. Infoblox considers such security research to be “authorized” under the Computer Fraud and Abuse Act.

We understand that Infoblox systems and services may be interconnected with third-party systems and services. While we can authorize research on Infoblox’s systems and services and waive our right to bring claims against any reporting efforts under this Policy, we cannot do so for third-party products; such security research on third-party products is done at your own risk. However, Infoblox will confirm that we authorized your efforts to test and research the security on Infoblox’s eligible systems and services in accordance with this Policy to a third party upon request.

If you’re unsure whether your conduct complies with this Policy, contact us first.

NONCOMPLIANCE:

Public disclosure of the submission details of any identified or suspected vulnerability without express written consent from Infoblox will deem any related submission as noncompliant with this Policy. This restriction does not prevent Infoblox from assigning a CVE ID, publishing a CVE Record or issuing a security advisory in accordance with the CVE Program Rules, or from making an earlier disclosure when necessary to protect customers, address active exploitation or comply with law. In addition, to remain compliant with this Policy, you cannot:

  • Access, download, or modify data residing in an account that does not belong to you;
  • Execute or attempt to execute any “Denial of Service” attack;
  • Post, transmit, upload, link, send, or store any malicious software;
  • Test in a manner that results in sending unsolicited or unauthorized junk mail, spam, pyramid schemes, or other forms of duplicative or unsolicited messages;
  • Test in a manner that may degrade the operation of any Infoblox properties; or
  • Test third-party applications, websites, or services that integrate with or link to Infoblox properties.

OUR COMMITMENT:

If you identify a valid security vulnerability in compliance with this Policy, Infoblox commits to:

  • Work with you to understand and validate the issue; and
  • Address the risk if deemed appropriate by the Infoblox PSIRT.
  • Acknowledge and triage reports according to the response targets in this Policy.
  • Assign CVE IDs for eligible vulnerabilities within Infoblox’s CNA scope and provide an assigned CVE ID to the reporter.
  • Publish the associated CVE Record and a public security advisory or other public vulnerability information in accordance with the CVE Program Rules and this Policy.
Back To Top