Reporting a Vulnerability

A clear venue to report potential security vulnerabilities.

Why report?

Vulnerabilities pose a potential risk to users and to the stability and reliability of devices and networks worldwide. Input from both internal and external resources plays a critical role in ensuring the security and overall quality of our open standards continually evolves. We welcome vulnerability reports from institutes, universities, independent researchers, and security professionals. The Alliance and its members are grateful for the public checks on our technology that allow our experts to investigate and address issues appropriately.

What to Include

To help our security team review your report efficiently, please include the following information. Reports missing required details may experience delays, as our team will need to follow up to request what is missing before the review can proceed.

Required
  • Descriptive title
  • Summary of the vulnerability and its potential impact
  • Detailed, clear description of the issue, including root cause if known
  • Steps to reproduce the issue
  • Affected protocol or specification (Matter, Zigbee, Aliro, Product Security, or other)
  • Specification version and section reference, if applicable
  • Device, module, or SDK component involved, including manufacturer and model if known
  • Proposed CVSS v4.0 score and vector
  • Validation method: please indicate whether this issue was manually reproduced by you,
    or identified through automated or AI-assisted analysis without manual confirmation
Optional, but helpful
  • Proof of Concept (PoC) code, script, packet capture, or log evidence
  • Suggested remediation or mitigation
  • Requested Disclosure Timeline

We kindly ask that all required fields be completed before submitting, as incomplete reports cannot be processed until this information is received. You can use our report template below to help structure your submission. Thank you for helping us keep the Matter, Zigbee, and Aliro ecosystems secure.

How to Report

To report a vulnerability, please send the relevant information via email to security_reporting@csa-iot.org. Please include the details outlined in the What to Include section above, you can use our report template to help structure your submission. Our security team will review your report and follow up with next steps.

Encrypting your report is optional but recommended if your message contains sensitive details. If you would like to encrypt your communication, you may use the following public PGP key:

-----BEGIN PGP PUBLIC KEY BLOCK-----
mQINBGLtXGEBEAChDHJS9S6fpAEa8dU1AD3BM7ThMy+LdR6ycIhcIFI6seXxWsif
VIC3cfNY/AylB8S4Y4YneO3icGvQA5Q+gpThmsUuLRnNunzyJJcYTvLiwmi6Ulyd
vXffijUlO6hTIg61DvpUxtVQsG5y50fUmaIQG7n4Eq+rq9UUfCLtlxPAkzeh6SOp
B7oHwQp0xMq8Q25/WOx79xTAmVfhS8VFxTTNfWzk0GQB7Vx1keeA9MZS33GpavS0
8Rc1OgA+Mi5qmViCsP45nuJfqw+nSB2MIET5IuzhMEZw6wxUblJtbeWNKjzFNaJc
xZotJWJVBrf+8Yr3OTKE3p+EXhcHrQJ0coWauJCWLsnGDzAPzyrJcCJjWwA4ghab
T95beMZhH+v+jaikXjl8udj2pC8Yg4tEQ6CYs7hK/wWnhobCTrbX+Sgqi/4x7cdE
Vp0mKlmIGKPsVZfqVJB+Qi2yhl7GiQCBMccdJjyuuNFLrR9w/Z0afM5f4LRKM93O
tjsgXrGIdx9oefLv8/ECvphuyBqdRSQuEEitd0uEjiA5sgRH5QLOk+nSkzVCvbCp
7Xe3VRLi0KmXo0ex2vpQSkPGmKxB4+q5Iri0zNq4Dj8qXlW9992DMYFFVir+tblp
Ee/V0a9PXp2tQMwvs55n0EYuj5c1f6hBcH+axJ5vLGNWPzPmUgvNNwia7wARAQAB
tDdDU0EgU2VjdXJpdHkgUmVwb3J0aW5nIDxzZWN1cml0eV9yZXBvcnRpbmdAY3Nh
LWlvdC5vcmc+iQJXBBMBCABBFiEEVXSuXQUhg5z4FF/oqEHTbDpYv+8FAmLtXGEC
GwMFCROTE78FCwkIBwICIgIGFQoJCAsCBBYCAwECHgcCF4AACgkQqEHTbDpYv+9d
tBAAjx9HuZ2YcKFtaFeyrVPzqVzehZYCcGoNklDGhnsyJpAkxLbuz9dlK616ANuj
OgAFMC/dE4hX2YHwnhrsHzVGycLC877fAiB3+LRdkBQOjfpbpWEcDQXSaDNzBNnb
DohZVgn1koyUHT0JhG/gK++lADOZYeLvpQcvqAhkOAxd80hwHiDmKmRFrg2SfVGX
TivallGKIOG+ULMaZ6qYT8S0Cr9xtgdzNoQNfL/qjq+gmTuumHUXfoi5lnPIoZZQ
qMi2pXKZxEQuc5PZVz3sQzjWI3Av26mjUxOuSXHyTcl79m3vZjs5DvwpEpCaUHiC
/FgAlTZQ/6B7uqDnXTMZ3oVy4NHhdx8t7lMRTHAgnZ1loxezT3DWuwKUFuGymugW
WTtWwn/zq7g32gQgfU+HNO9oct6DeRjYlf+GFvN1A1pY+LetuTV/ptlViKZst6yn
QeJ01/bP0BEJ2ueUUPyATETglCTaO/rfHOtXqh9Z9e1uoqipOKSo2ERF/50wFRY1
VFVEm09vGjfQPSfrmZPvENZdYM0sUpqFHAO/A7tJ6jOYLRsOfY0dezNo2Mdy0q3o
vivxksh0XWh+E+e9GeRn75SOWa28jq4WuJJ6XKpysWLmVJeitYqV/wuMcPUE2Ph4
aYgor3a0rE0EihzKkiPpxxT//qEsqXPBXYoBNXLHBWEq9Bq5Ag0EYu1cYQEQALZa
tfcpS1OYHqBHiJKqN9ZXqW6+T9uBL8GF3O5XhYQoVyikvjAA7r1gxRUG6UyNk9V7
sjfp6iHQHg527bKe0XkywpRr/aYm9gmTYLLiNEviqJLlIIIFGIQSdP48jrZfKk7C
asTJCJjFtEei+a7jFapWL9uKTw89okkZRwjbWL8jl69Y7c9PmJInBMiCAr/jpj6d
TIM35Wnn0l5wFxnG+SSDjaz7zlXbjmA7Qthx6pNh13aUc9geRDaABWT+8rtK5PCa
C5sB1Ym8ACQhsjMgSkadNWzZSkkwDwOXG+OM5xn4792aP8WNYATuxzbJvLlz1aEW
Armgfne8O6a9ZnRuN+iZMOpl9HJgX7rCaYlRxAix7phLFSdW80KJ6W239oNdEcXI
ygnoTPNCQMBsfKHn25Q6mdzqix9hrGTCrgDfcUgTv7S2hDq0u0mJvTvVeAz1B7t8
9lfyXKqgAJsPn8GjP8XTLwP5Tn4jbeud4RJqbfoMAdm1ahAC8Ksm+6dyc95/rugS
bkui9n33o0EKOzwQCuY42vOiK3nBJa2P+EgKN4iCiweT3VkpxI9gGToWIaW1uaKp
PdRwbhnv1dPQzQVRxezW5bX/y0i+sT11tVuQA6XtLBt+AYuR/M/NW+DclXQnJje3
lEIVr2obxZGKG4Y0HT+HZN46T1649xqu+xp2GjrHABEBAAGJAjwEGAEIACYWIQRV
dK5dBSGDnPgUX+ioQdNsOli/7wUCYu1cYQIbDAUJE5MTvwAKCRCoQdNsOli/70fQ
EACGC8cIvo+zxK1f1qZAkMEcnY097DY7JYn19mAxGiiLic9WEgCgkyiBK/NRXfNm
Ciw8fToGF13djmSTr4w6kcbrLOTcqPycgJSFjBJdwDyC/WZuqQETUj1tM0S2ge1l
e35HnoZmGVJ9jG2NRE0uXFXahKX3Rj06MddveQfsWSYXllZLg0jvuQe5NZhx1Mb0
1zIxswbWI3P+1dYQRnmA2AkoCL4SNjinJyQiIkGnkkBzi+trDwvSTvEmE83/LiPn
7y0b3uFiO7WCco52YuhPTiWZEUjhQWWdW+U/YeyU8Gc5/lEe9n8afeoim8g1qZ+c
cWleKn/VRMusSW1rYK5KuV7fb27DleVlvXPeLM3WlRdtLWpm79ZjZ+bdec8B7lM8
V+5234T97HLYnkVP+mvxmweNaB6q8R09/Hs7Y/s9M7gskRL5FTbx3JXTo8u4P3/b
mtMNzuOnHa+IOkpdAur3YscZioIm8tDvSB07k5PXmiHf7+kFMPi2rLJkGg2gISYQ
7SZa6DBq0eIXfNBU44c2PsHkfw6OMhAknt8AY9tF94T1EVnKIULylgvclvaKDce7
M0EIzkYJg/KVAEfmuA2ZN0RHL9Mb15U17qBa9eb4GshZi05J58mbfI5HBH4LFzJ5
iUQAO9rNNSLsQyF1y5m3rSCrL6RYPXBLixl5Lzvq/BI1FA==
=YG9f
-----END PGP PUBLIC KEY BLOCK-----
Vulnerability Report Template

You can use the template below to structure your report. Required fields are marked with an asterisk (*).

Title (*):
Summary (*):
Description (*):
Steps to Reproduce (*):
Affected Protocol/Specification (Matter, Zigbee, Aliro, Product Security, other) (*):
Specification Version / Section Reference (*):
Device, Module, or SDK Component Involved (*):
Proposed CVSS v4.0 Score (*):
Proposed CVSS v4.0 Vector (*):
Validation Method (manually reproduced / automated or AI-assisted, unconfirmed) (*):
Proof of Concept (PoC):
Suggested Remediation:
Requested Disclosure Timeline:

Certification Creates Confidence

Certification validates compliance  with a Connectivity Standards Alliance specification. It also allows for the use of Certified Product logos on packaging and products, building trust and confidence with customers and consumers.

Get Certified Today


Let’s Connect

Have a question? We’re here to help. 

Contact Us