- Product Security
- Vulnerabilities Disclosure Policy
- Public Vulnerability Information List
- Report a Product Security Issue
Product Security
We provide information on the product security of Lighthouse (UK) Ltd
1. PURPOSE
Lighthouse (UK) Ltd is committed to ensuring the security of our products and services throughout their lifecycle,
and to protecting our users and customers.
The Vulnerability Disclosure Policy describes how security vulnerabilities can be reported to us and how we handle
such reports.
2. SCOPE
This policy applies to our products with digital elements and related components we maintain.
Lighthouse (UK) Ltd does not accept the following reports:
• Vulnerabilities in products that are longer supported
• Social engineering attacks
• Denial-of-service attacks
• Vulnerabilities that cannot be reproduced
• Vulnerabilities that have already been disclosed
• Reports indicating non-compliance with the security guidelines
3. LIFECYCLE
The lifecycle of the products listed below relates to any product that is current generation or manufactured in the
last 5 years.
• CJ80
• Letatwin
• CJ-Pro II
• CPM-100 G5
• CPM-100 HG5
• CPM-100 SHG5
• CPM-200
4. REPORTING OF VULNERABILITY
If a vulnerability is discovered in Lighthouse (UK) Ltd.’s products, please report on the website using the following
link https://www.lighthouse.uk.com/security-vulnerability/ providing the following information:
• Product name and serial number
• Description of the issue
• Impact of the vulnerability
• Your contact details
Lighthouse (UK) Ltd will acknowledge receipt of the report within seven working days, and may request further
information if required. The reporter will be kept informed as appropriate until remediation is available.
Lighthouse (UK) Ltd does not provide any rewards, regardless of the content of the report.
5. REMEDIATION AND DISCLOSURE APPROACH
Lighthouse (UK) Ltd will prioritise remediation based on severity and exploitability. We aim to provide a fix or
mitigation within 90 days where feasible, and we will coordinate extensions when necessary.
Once countermeasures for vulnerabilities in the products and services are completed, we will coordinate with
relevant organisations to schedule the disclosure information. This information, including details of the
vulnerabilities and corresponding corrective measures will be published on our website.
In addition, in accordance with applicable laws and regulations, Lighthouse (UK) Ltd will report to external security
authorities and coordinating organisations as required.
Vulnerability Information
No updates yet.
Report a potential security vulnerability to lighthouse (uK) Ltd
Please use the form below to report potential security vulnerabilities in Lighthouse (UK) Ltd supported products to the Lighthouse (UK) Ltd Product Security Response Team. For reports regarding to the Letatwin, please visit our parent company website here.
For all other issues, please use the contact page on our website to choose the contact option best suited to your enquiry.
The Lighthouse (UK) Ltd Product Security Response Team is dedicated to reviewing and responding to reports of potential security vulnerabilities in a timely manner. Any reports submitted that are not related to potential security vulnerabilities in Lighthouse (UK) Ltd products may be forwarded to the appropriate team within Lighthouse (UK) Ltd. Please note that forwarding a report may delay our response.
Please note that the Lighthouse (UK) Ltd Product Security Response Team is currently limited to enquiries and responses written in English.
