Melexis Commitment
At Melexis, we recognise the paramount importance of safeguarding information and products. In today's interconnected world, where data drives innovation and sustains business operations, maintaining the confidentiality, integrity, and availability of our information assets is not just a goal but a fundamental responsibility.
As stewards of critical data, we declare our unwavering dedication to cyber security. We understand that protecting our information assets and securing our products is not only essential for our own success but also for the trust our clients, partners, and stakeholders place in us.
Reporting Guidelines: What to Report?
To ensure the Melexis security team receives actionable data and to minimize unrelated submissions, the webpage must clearly define what is in-scope and out-of-scope for product vulnerability reporting.
| In-Scope Melexis Products | Out-of-Scope / Exempted |
| Melexis integrated circuits (ICs), sensors, placed on the EU commercial market. | Denial of Service (DoS) & Spam: Volumetric attacks, brute-force, or automated form submissions. |
| Standalone hardware developer and programming toolsets (e.g., Melexis PTC-05 programmer). | Social Engineering & Phishing: Attacks targeting employees or users, or requiring improbable user interaction. |
| Embedded software, firmware, and ROM codes developed by Melexis. | Information Disclosure: Software versions, path/stack traces, banner grabbing, or username enumeration. |
| Melexis internet-exposed assets, websites, and cloud assets. | Best Practices & Security Headers: Missing HTTP security headers (HSTS, CSP, etc.), cookie flags on non-sensitive cookies, HTTPS mixed content, or weak CAPTCHA/password rules. |
| Low-Impact Vulnerabilities: Unauthenticated CSRF, non-HTML content injection, or issues limited to outdated/EOL browsers and products. |
Next steps after form submission
Upon submission through the web form or encrypted email to [email protected], the Melexis Security team will execute the following standard operational steps:
- Technical Triage & Acknowledgment
Receipt is logged and a confirmation is sent to the reporter. - Analysis and Impact Assessment
The Melexis security team analyzes the report to verify exploitability and assess risk severity. - Remediation & Patching
Corrective patches or physical mitigations are engineered without undue delay. - Coordinated Vulnerability Disclosure
According to Melexis policy
PGP public key
To send an encrypted report by email, use the Melexis Security Office public PGP key. Verify the fingerprint before use.
| Fingerprint | A787 A292 7982 1E17 2E57 B431 8B48 AAE0 4816 EF7D |
| [email protected] |
-----BEGIN PGP PUBLIC KEY BLOCK----- mDMEap8KZhYJKwYBBAHaRw8BAQdAvHtMZU+XQFCMwkvC0OZAV0AxxBLX1J39nP2N YYuJMey0NE1lbGV4aXMgU2VjdXJpdHkgT2ZmaWNlIDxzZWN1cml0eW9mZmljZUBt ZWxleGlzLmNvbT6IkwQTFgoAOxYhBKeHopJ5gh4XLle0MYtIquBIFu99BQJqnwpm AhsDBQsJCAcCAiICBhUKCQgLAgQWAgMBAh4HAheAAAoJEItIquBIFu99In8A/0a3 TyGCu2OMoXHabbNxeJwYtmERdoZXIhH53+bcGGAEAP9KAzTvxZvEmd/o/qMuLoeD 5EcZYrSZVGOM35MZ3bcjDbg4BGqfCmYSCisGAQQBl1UBBQEBB0D4osIYWC/YnZKE f8PehUb8LnF61lj1DxCpPQGTxz+bYwMBCAeIeAQYFgoAIBYhBKeHopJ5gh4XLle0 MYtIquBIFu99BQJqnwpmAhsMAAoJEItIquBIFu99LIgA/1cBzy0SqnSrtU7AGVO6 Pi/ImJQoWw2W2mlwuX6I9o1CAQCBkx5YN/sIbyiEpdEQEgthJ2W2W0RZ6Y7d1QGP 8WAdAQ== =ZSr9 -----END PGP PUBLIC KEY BLOCK-----
CVE Security Advisories
Melexis will publish formal security advisories for validated exploitable vulnerabilities only after a secure patch or remediation is available. Currently, no CVE exists related to Melexis products.