Welcome to Micron.com, please Log in or Register an account to continue.
Micron Vulnerability Disclosure Policy
Purpose
At Micron, our vision is to transform how the world uses information to enrich life for all, and our mission is to be a global leader in memory and storage solutions. We cannot achieve our vision and mission without steadfast dedication to providing comprehensive security for our solutions, respecting your privacy, and protecting your data. To support this commitment, Micron welcomes feedback on potential vulnerabilities involving our products. Ultimately, by receiving this information, we will be better able to continue providing trustworthy products to our customers.
This Vulnerability Disclosure Policy (“policy”) outlines steps for reporting potential vulnerabilities in Micron products to Micron and describes what you (i.e., our reporting sources, customers, and the public) can expect in return.
Scope
This policy applies to all Micron-branded products.
Policy Statement
Micron performs coordinated vulnerability disclosure. To minimize risks to customers that may be posed by identified potential vulnerabilities, Micron does not publicly disclose information about such vulnerabilities until we have conducted an analysis of the affected product, validated the vulnerability, coordinated with relevant stakeholders, and determined and executed the appropriate remedy or other mitigating action.
Expectations
When working with Micron pursuant to this policy, we ask reporting sources to:
- Report a potential vulnerability to us as soon as possible.
- Use the reporting channels that are described in this policy and on our website to report an issue to us.
- Coordinate with us to establish and implement an embargo (i.e., a time period during which neither of us will disclose details pertaining to the reported matter to others).
In return, those that provide a report to Micron can expect us to:
- Send an email acknowledging receipt of your report.
- Confirm and work to remedy potential vulnerabilities identified by the reporter. The amount of time needed to resolve an issue may vary depending on the type of identified vulnerability (including whether software or hardware is potentially affected).
- Strive to keep you informed of investigation, validation, and remediation activities as permitted by Micron policies and relevant supplier or customer agreements.
- Protect customer-specific data from disclosure throughout the process pursuant to this policy.
Currently, Micron does not offer or participate in standing bug bounty programs. While we do not honor requests for bounty payments, we may provide credit within a Security Bulletin to a reporting source.
How to Report a Vulnerability
The following methods should be used to report a potential vulnerability involving a Micron product:
- Web Form
- Using the Micron PSIRT PGP Key, send email with the following information to: psirt@micron.com
- Product name and version
- Type of vulnerability (code execution, DoS, buffer overflow, etc.)
- Environment/Operating system
- Process to replicate issue/Proof-of-concept
- Any security impact or concerns associated with the vulnerability
- Reporting to your Micron sales representative, as relevant
Micron Product Security Incident Response Team
Micron’s Product Security Incident Response Team (PSIRT) is responsible for the identification, assessment, and disposition of risks related to potential vulnerabilities involving Micron products. Our PSIRT manages issues reported to Micron through both external and internal channels, and our PSIRT processes and procedures follow guidelines and best practices such as those prescribed by the Forum of Incident Response and Security Teams (FIRST) and the International Organization for Standardization, to include ISO/IEC 29147:2018 and ISO/IEC 30111:2019.
Micron PSIRT uses FIRST’s Common Vulnerability Scoring System version 4.0 (CVSS v4.0) to rate the severity of validated vulnerabilities involving Micron products. The CVSS v4.0 model enables a common scoring method and a common language to communicate the characteristics and impacts of exploitable vulnerabilities. The scoring system consists of four metric groups (Base, Temporal, Environmental, and Supplemental) that establish a measurement of how much concern a vulnerability warrants by assigning a numerical value.
Communications Plan
After all remediation activities are complete and notification has been provided to relevant stakeholders, Micron may issue and post a Security Bulletin about a validated and remediated vulnerability. The Security Bulletins may include the following information, when applicable:
- Affected product and version
- Common Vulnerability Enumeration (CVE) identifier for the vulnerability (see https://cve.mitre.org)
- Brief description of the vulnerability and potential impact if exploited
- The CVSS severity rating for the vulnerability (see https://www.first.org/cvss/user-guide.html)
- Remediation details such as security update, mitigation, or other action
Credit within a Security Bulletin may be provided to the reporter of the identified vulnerability for working with Micron on the coordinated vulnerability disclosure. The credit will only be provided if:
- The vulnerability impacts a currently supported Micron product.
- We implement a remedy or other mitigating action based on the reported issue.
- You are the first source to report the issue to us.
- Your research aligns with this policy, and you consent to inclusion of the acknowledgment.
Disclaimer
Notwithstanding the foregoing, Micron does not guarantee a specific resolution for every reported issue; only those determined to be a valid vulnerability will be addressed.
Additionally, Micron reserves the right to: (1) bring timeframes noted in this policy forward or backward; (2) perform processes different from those described in this policy if necessary; (3) deviate from application of the CVSSv4.0 model if additional factors warrant use of other scoring systems; and (4) change or update this policy without notice at any time.
Information that is disclosed pursuant to this policy is believed to be accurate and releasable at the time it is furnished. Micron assumes no responsibility for the consequences of use of such information or for any infringement of patents or other rights of third parties that may result from its use.
Micron customers’ rights with respect to warranties and maintenance in any Micron product are governed by the Terms and Conditions of Sale, Legal Terms and Warranty, or Warranty statements for each product. This policy does not modify or expand any customer rights or create any additional warranties.