Używamy plików cookie, które są małymi plikami tekstowymi, aby poprawić komfort korzystania z naszej witryny i pokazywać spersonalizowane treści. Możesz zezwolić wszystkim lub zarządzać nimi indywidualnie.

Vulnerability Disclosure Policy

Vulnerability Disclosure Policy

At Creative we are committed to building secure and resilient products and services. We welcome good faith reports of suspected vulnerabilities affecting Creative products, software, systems, or services, and we value those who help us identify and address security issues responsibly. Please review this policy carefully before conducting any research or submitting a report.

Scope

For purposes of this policy, "Creative products, software, systems, or services" includes:

  1. Creative-branded consumer audio hardware devices and the embedded firmware running on them, including firmware distributed through over-the-air (OTA) or other update mechanisms (each such device, together with its embedded firmware, a "Creative Device");
  2. wireless and radio interfaces (including Bluetooth and Wi-Fi);
  3. companion desktop and mobile applications; and
  4. the associated cloud or backend services that support the foregoing, including firmware/OTA update servers, user account and authentication systems, and application backend services.

Research conducted on a Creative Device that you have lawfully purchased and own is within scope. Testing of the companion applications and the associated cloud or backend services is within scope only to the extent conducted against accounts, data, or assets that you own or are expressly authorized to assess, or against public-facing assets that Creative has expressly identified as in scope. All research remains subject to the guidelines and prohibited activities set out below.

How to Submit a Report

When submitting a vulnerability report, please provide sufficient information to enable Creative to reproduce and assess the issue. Where available, your report should include:

  • a clear description of the suspected vulnerability;
  • the affected product, software, service, model, and version;
  • the technical details and conditions necessary to reproduce the issue;
  • the potential impact of the vulnerability; and
  • your contact information so that we may communicate with you regarding the report.

We ask that researchers make reasonable efforts to avoid harm during security testing. Please do not take any action that could impair the confidentiality, integrity, availability, or safety of Creative products, software, systems, or services, or associated data. In particular, do not disable, bypass, or interfere with any product safety feature (including volume-limiting or hearing-protection controls) in a manner that could create a risk of physical harm to any user. Avoid accessing or retaining data beyond what is necessary to demonstrate the vulnerability, and stop testing immediately if you encounter sensitive data or risk service disruption.

Confidentiality and Coordinated Disclosure

Please maintain the confidentiality of your findings, along with any related information you learn or infer through your research, until we have completed our investigation and, where appropriate, implemented any necessary measures, and/or until we've coordinated disclosure with you. This helps protect our users and ensures the responsible handling of security issues. We'd appreciate you keeping this in mind even where we decide not to remediate, and even where the same or a related vulnerability might affect other Creative products, software, systems, or services that share a common component (for example, a chipset, codec, wireless stack, or licensed firmware).

Creative’s Response

Upon receipt of a report submitted under this policy, Creative will endeavor to:

  • acknowledge receipt of the report;
  • review the submission and determine whether additional information is required;
  • investigate the reported issue using appropriate internal resources;
  • prioritize remediation based on the nature, severity, exploitability, and potential impact of the vulnerability; and
  • communicate with the reporting party as appropriate during the review process.

Creative will use reasonable efforts to review reports and address confirmed vulnerabilities in a timely manner, but response and remediation timelines may vary based on issue complexity, product lifecycle, and operational constraints.

Guidelines for Permitted Research

This policy applies only to good faith security research conducted in a manner consistent with its terms. To remain within scope, you must:

  • act lawfully and in good faith;
  • avoid privacy violations, service interruption, destruction of data, and degradation of user experience;
  • test only against products, services, accounts, or assets that you own or are expressly authorized to assess, unless Creative has expressly identified particular public-facing assets as in scope for testing; and
  • promptly report any vulnerability discovered without exploiting it beyond what is reasonably necessary to confirm its existence.
  • conduct any wireless or radio-frequency testing (including Bluetooth or Wi-Fi) only against your own devices and in a manner that does not interfere with other users, devices, or licensed spectrum; and where a suspected vulnerability originates in a third-party component (for example, a chipset, codec, or licensed firmware supplied by another vendor), notify Creative so that we may coordinate with the upstream vendor as appropriate.

Activities to Avoid

To keep your research in scope and protect our users, please avoid the following activities, which are not permitted under this policy:

  • accessing, downloading, modifying, or deleting data belonging to others without authorization;
  • conducting testing that intentionally or recklessly disrupts or degrades Creative products, software, systems, or services;
  • using invasive, excessive, or disruptive automated scanning or testing methods against Creative infrastructure;
  • exploiting a vulnerability for any purpose other than its minimal verification;
  • engaging in phishing, pretexting, social engineering, or other deceptive practices against Creative personnel, users, customers, or partners;
  • conducting physical attacks against Creative Devices that you do not own (physical examination, teardown, or firmware extraction of a Creative Device that you have lawfully purchased and own is permitted, provided it does not endanger any other person or device);
  • conducting wireless pairing, testing, commands injection against Creative Devices that you do not own;
  • publicly disclosing a vulnerability before Creative has had a reasonable opportunity to investigate and remediate it.

Out of Scope Reports

Certain categories of findings are outside the scope of this policy or may not be prioritized for response. These include, without limitation:

  • reports based solely on automated scanning output without a clear demonstration of an actual security risk;
  • missing security best practices or theoretical weaknesses without a demonstrable exploit path or meaningful impact;
  • reports concerning end-of-life, outdated, or unsupported products, firmware, or services no longer maintained by Creative;
  • version disclosure, banner disclosure, stack traces, path disclosure, or verbose error messages that do not lead to a demonstrated security consequence;
  • weak SSL/TLS configuration findings or other cryptographic observations that do not present a clear, exploitable risk in context;
  • findings that require unlikely user interaction, physical access, man-in-the-middle positioning, or prior compromise of another account, unless significant security impact is clearly demonstrated; and
  • denial-of-service or resource exhaustion findings obtained through active testing, whether or not actual service disruption occurred.

Creative reserves the right to determine, in its discretion, whether a submission falls within scope and the priority assigned to it.

Legal Statement and Safe Harbor

If you conduct security research in good faith and in compliance with this policy, Creative will not initiate legal action against you solely on that basis, though we cannot bind third parties or law enforcement authorities.

This Safe Harbor applies only to the extent permitted by applicable law and only to claims Creative may bring on its own behalf. It does not provide immunity from third-party claims or liability under applicable law. If a third party initiates legal action in connection with activities Creative determines were conducted in compliance with this policy, we may, in our discretion, indicate that we regard such activities as authorized, but we are not obligated to provide legal representation, indemnification, or other support.

No Reward Program

While we are grateful for the time and effort researchers invest, this is not a paid program. Unless Creative expressly states otherwise in writing, submission of a report does not entitle the reporting party to any payment, bounty, compensation, public recognition, or other benefit.

Changes to This Policy

Creative may update, revise, suspend, or withdraw this policy at any time. The version in effect at the time the relevant activity occurred will govern Creative’s assessment of compliance.

Contact Information

To report a vulnerability or ask questions about this policy, please contact Creative through the security reporting channel via the form below.

Twoje dane

Wprowadź imię.

Wprowadź nazwisko.

Kraj Afghanistan Albania Algeria Andorra Angola Anguilla Antigua Argentina Armenia Aruba Australia Austria Azerbaijan Bahamas Bahrain Bangladesh Barbados Belarus Belgium Belize Benin Bermuda Bhutan Bolivia Bosnia and Herzegovina Botswana Brazil British Virgin Islands Brunei Bulgaria Burkina Faso Burundi Cameroon Canada Cape Verde Islands Cayman Islands Central African Republic Chad Chile China Christmas Island Cocos-Keeling Islands Colombia Comoros Congo Congo, Democratic Republic of the Costa Rica Croatia Cuba Cyprus Czech Republic Denmark Djibouti Dominica Ecuador Egypt El Salvador Equatorial Guinea Eritrea Estonia Ethiopia Falkland Islands Faroe Islands Fiji Islands Finland Former Yugoslav Republic of Macedonia France French Guiana French Polynesia Gabon Gambia Georgia Germany Ghana Gibraltar Greece Greenland Grenada Guadeloupe Guam Guatemala Guinea Guinea-Bissau Guyana Haiti Honduras Hong Kong SAR, PRC Hungary Iceland India Indonesia Iran Iraq Ireland Israel Italy Jamaica Japan Jordan Kazakhstan Kenya Kiribati Republic Korea (North) Korea (Republic of) Kuwait Kyrgyz Republic Laos Latvia Lebanon Lesotho Liberia Libya Liechtenstein Lithuania Luxembourg Macau Madagascar Malawi Malaysia Maldives Mali Malta Marshall Islands Martinique Mauritania Mauritius Mayotte Island Mexico Micronesia, Federated States of Moldova Monaco Mongolia Montenegro Montserrat Morocco Mozambique Myanmar Namibia Nepal Netherlands Netherlands Antilles New Caledonia New Zealand Nicaragua Niger Nigeria Niue Norfolk Island Norway Oman Pakistan Palau Panama Papua New Guinea Paraguay Peru Philippines Poland Portugal Puerto Rico Qatar Reunion Island Romania Russia Rwanda Saint Barthelemy Saint Kitts & Nevis Anguilla Saint Lucia Saint Martin San Marino Sao Tome and Principe Saudi Arabia Senegal Republic Serbia Seychelle Islands Sierra Leone Singapore Slovak Republic Slovenia Solomon Islands Somalia South Africa Spain Sri Lanka St. Pierre and Miquelon St. Vincent and the Grenadines Sudan Suriname Swaziland Sweden Switzerland Syria Taiwan Tajikistan Tanzania Thailand Togo Tokelau Tonga Trinidad and Tobago Turkey Turks and Caicos Islands Ukraine United Arab Emirates United Kingdom United States of America United States Virgin Islands Uruguay Uzbekistan Vatican City Venezuela Vietnam Yemen Zambia Zimbabwe

Wybierz kraj

Wybierz język English Deutsch Français Italiano Polski Español Russian 繁體中文 简体中文 日本語

Wybierz preferowany język odpowiedzi.

Twój komentarz jest za krótki.

Twój komentarz jest za długi.

Wpisz komentarz.

Błędna odpowiedź. Proszę spróbować ponownie.
Wyślij