Security Vulnerability Disclosure & Bug Bounty Policy
Silicon Labs is a leader in secure, intelligent wireless technology for the connected world. Our mission is to empower developers to create wirelessly connected devices that transform industries, grow economies, and improve lives. The security of our corporate infrastructure and product technologies is critical to our business, to growing customer relationships, to maintaining the trust of our users, and to doing the right thing. Silicon Labs recognizes the important role that security researchers play in keeping our systems and products secure and values our relationship with the security community. Silicon Laboratories Inc. (“Silicon Labs”, “we”, or “our”) looks forward to working with the security community to find vulnerabilities to keep our businesses and customers safe.
Silicon Labs recognizes the important role that security researchers play in keeping our organization, our customers, and our users safe. We believe that working with skilled security researchers is critical in identifying and remediating weaknesses in any technology. If you’ve identified a potential security vulnerability in our product, services, or infrastructure, please report it to us as soon as possible. We look forward to working with you and doing our best to address the issue quickly.
If you have found a vulnerability, please register or log in as a researcher on the Silabs Community Page, and a form will be provided for your vulnerability report.
The list below defines the scope of the Silicon Labs VDP and Bug Bounty program:
- Newly discovered security vulnerabilities that occur with Silicon Labs products, reference designs, web assets, or enterprise infrastructure and are not already covered in published documents/forums.
- Silicon Labs infrastructure, products, or systems that are being used or accessed unexpectedly.
- Does not include sample/example applications in the SDK or GitHub repositories.
Abbreviations/Definitions
- PCN – Product Change Notification
- PSIRT – Product Security Incident Response Team
- ESIRT – Enterprise Security Incident Response Team
- RFI – Request for Information
Reporting a Vulnerability
The security of our products and infrastructure is critical to our business. This program is a key part of our security strategy. We recognize your time and effort and are committed to doing the right thing for our researchers, customers, and users. Payouts are based on CVSS scores as determined by the Silicon Labs PSIRT team and will follow our response targets and rewards structure as shown below. Vulnerabilities or suspicious functionality in products may be reported by customers (via their supporting Field Applications Engineers), Silicon Labs employees (via internal reporting method), and researchers or other interested parties (via our Silicon Labs Community Page). When a security vulnerability is suspected, please register or log in as a researcher on our Silicon Labs Community Page, and a form will be provided for your vulnerability report.
Security Response Process
When a security vulnerability is suspected, complete and submit a report. The report will be sent to the Silicon Labs PSIRT/ESIRT team. An acknowledgment by Silicon Labs will occur within three business days of receipt of the report, and triage by Silicon Labs will follow the response targets below.
Our ESIRT and PSIRT work with other Silicon Labs groups including Applications Engineers, Engineers, Developers, Product Managers, Sales, and Marketing to assess reported vulnerabilities, perform technical analysis, and determine an appropriate response. The key processes for addressing vulnerabilities include:
- Triage: This involves active dialog between the ESIRT/PSIRT, the reporting entity, the Applications Support Team, as well as the Engineering Design team, to determine what is needed to reproduce the vulnerability.
- Next Steps: This involves the actual confirmation of the validity of the security vulnerability based on the issue’s evaluation and/or reproduction. The scope and impact or severity of the vulnerability are confirmed, as well as a resolution or disposition decision. This may include a fix, workaround, or acceptance of the identified vulnerability.
- Output: This conditionally includes an official fix, recommended mitigating actions, assignment of CVE ID(s), and an official Silicon Labs security advisory. The level of disclosure beyond the reporting entity will depend on the severity and scope of the vulnerability.
Response Targets
Silicon Labs will make reasonable efforts to meet the following SLAs for participants in the program:
| Type of Response | ESIRT SLA in business days | PSIRT SLA in business days |
|---|---|---|
| First Response | 3 days | 3 days |
| Time to Triage | 15 days | 15 days |
| Time to Resolution | Depends on severity and complexity | Depends on severity and complexity |
Our Approach to Bug Bounty
We are excited to work with you to make our products more secure and strengthen our engagement with the security community. We strive to:
- Be as transparent as possible.
- Reply to reports as quickly as possible to reduce the likelihood of duplicate work for our researchers.
- Compensate researchers as quickly as possible once we validate the report.
- Work with security researchers as peers and assume the best in interactions with the security community.
Bounties
Bounties are paid out based on the PSIRT priority according to the confirmed PSIRT priority rating, which is determined by a Silicon Labs review process. Once you register as a researcher at community.silabs.com, payments for the confirmed reported vulnerabilities will be based on priority as described in the Vulnerability Disclosure Program (VDP) FAQ.
Silicon Labs may, at its sole discretion, offer certain monetary rewards for vulnerability disclosure. Bounty amounts are determined by Silicon Labs and subject to the following eligibility requirements:
- Due to U.S. trade restrictions and/or export sanctions, we cannot issue payments to individuals residing in or reporting from countries subject to U.S. sanctions (as defined by the U.S. Office of Foreign Assets Control, including but not limited to Burma, China, Cuba, Iran, North Korea, Russia, Belarus, Sudan, Syria, and Venezuela).
- Minors may participate, but anyone under 18 must have a parent or legal guardian claim the bounty on their behalf to comply with COPPA and other applicable laws.
- All payments are made in U.S. dollars and must comply with local laws, regulations, and ethics rules. You are responsible for any applicable taxes related to any payments that you receive.
- You are responsible for complying with your employer’s policies regarding participation in this program
Disclosure Policy
- As a condition of participation, you agree that you will not discuss this program or disclose any vulnerabilities (even resolved ones) outside of the program without express consent from Silicon Labs.
Program Guidelines
To protect our company, customers, and users, you must accept and comply with the following guidelines:
- Do not disclose the potential security issue to any third party without Silicon Labs’ prior written permission.
- Reports must provide enough detail to reproduce the issue. If a report is not detailed enough to reproduce the reported issue, the issue may not be accepted as a vulnerability.
- Only one vulnerability per report unless vulnerabilities need to be chained to provide impact.
- If duplicates are received, only the first report received will be triaged (provided that it can be fully reproduced).
- Multiple vulnerabilities caused by one underlying issue will be treated as one valid report.
- Ensure your research complies with all relevant laws and regulations. Conduct research only on Silicon Labs products and websites, in accordance with their terms and conditions (e.g., Community Terms of Use, Master Service License Agreement, Terms and Conditions of Sale), and all publicly posted policies, guidelines, and instructions.
- Avoid privacy violations, destruction of data, and interruption or degradation of our services. Only interact with accounts you own or with explicit permission of the account holder.
- Do not engage in any spamming of our customers or potential customers.
- Do not engage in social engineering (e.g., phishing, vishing, smishing).
- Do not engage in any physical attempts against Silicon Labs property or data centers.
- Do no harm. Report vulnerabilities promptly and act for the common good; never exploit others without permission. If you confirm a vulnerability (e.g., proof-of-concept achieved) or encounter sensitive data — including personal, financial, proprietary, or trade-secret information — stop immediately and report it. Do not access, copy, modify, store, transfer, or further explore the data. Upon reporting, promptly delete any such information in your possession.
- Do not engage in any denial of service.
- Once a report is submitted, Silicon Labs commits to providing prompt acknowledgement of receipt of all reports (within three business days of submission) and will keep you reasonably informed of the status of any validated vulnerability that you report through this program.
- You give us the right to use the content of your report for any purpose.
- Submission of a report does not create a consumer, employment, or agency relationship between you and Silicon Labs.
- Silicon Labs may update this policy at any time.
Out of Scope Vulnerabilities for Web Assets
When reporting vulnerabilities, please consider (1) attack scenario/exploitability, and (2) security impact of the bug. The following issues are considered out of scope:
- Clickjacking on pages with no sensitive actions.
- Cross-Site Request Forgery (CSRF) on unauthenticated forms or forms with no sensitive actions.
- Attacks requiring MITM or physical access to a user's device.
- Previously known vulnerable libraries without a working Proof of Concept.
- Comma Separated Values (CSV) injection without demonstrating a vulnerability.
- Missing best practices in SSL/TLS configuration.
- Any activity that could lead to the disruption of our service (DoS).
- Content spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS.
- Rate limiting or brute-force issues on non-authentication endpoints.
- Missing best practices in Content Security Policy.
- Missing HttpOnly or Secure flags on cookies.
- Missing email best practices (Invalid, incomplete or missing SPF/DKIM/DMARC records, etc.).
- Vulnerabilities only affecting users of outdated or unpatched browsers [Less than 2 stable versions behind the latest released stable version].
- Software version disclosure / Banner identification issues / Descriptive error messages or headers (e.g. stack traces, application or server errors).
- Tabnabbing
- Open redirect - unless an additional security impact can be demonstrated.
- Issues that require unlikely user interaction.
Out of Scope Vulnerabilities for Products
- Eligible vulnerabilities should not rely on physical tampering of the device, but be restricted to what on-chip or off-chip software is exploitable; however, Side Channel Analysis and Fault Injection testing are in-scope for the program.
- General: alignment, cosmetic, documentation errors/spelling, incompatibilities between previous releases and the latest toolchain.
- Vulnerabilities in development branches (such as alpha and beta versions of code or features supported for development only).
- Any 3rd party software.
- Sample/Example code/programs.
- Vulnerabilities in deprecated releases.
- Any attack preventable by existing security features.
- Silicon Labs employees are expected to make submissions internally and are not eligible for the bug bounty program.
Policy on Repeat Bugs Across Multiple Assets
Silicon Labs often has the same code deployed in multiple branches, meaning that a single vulnerability is independently fixable in multiple locations. It is our policy to count this as one vulnerability for the sake of the Vulnerability Disclosure Policy/Bug Bounty. As such, we will only pay bounties on the first report of a vulnerability to a specific piece of code — vulnerabilities on multiple parameters in the same form will be treated as the same vulnerability.
High Priority Assets/Features
Silicon Labs is acutely interested in security issues related to the following components:
- Hardware Cryptographic Acceleration for AES128/192/256, ChaCha20-Poly1305, SHA-1, SHA-2/256/384/512, ECDSA+ECDH (P-192, P-256, P-384, P-521), Ed25519 and Curve25519, J-PAKE, PBKDF2
- True Random Number Generator (TRNG)
- ARM® TrustZone®
- Secure Boot (Root of Trust Secure Loader)
- Secure Debug Unlock
- DPA Countermeasures
- Secure Key Management with PUF
- Anti-Tamper Secure Attestation
- Wireless Stack
- Platform Security Features
- Gecko Bootloader
- Gecko SDK
- 917 bootloader
Miscellaneous
This program is not open to minors, individuals who are on sanctions lists, or who are in countries (e.g., Cuba, Iran, North Korea, Sudan, and Syria) on sanctions lists. You are responsible for any tax implications resulting from payouts depending on your country of residency and citizenship. Silicon Labs reserves the right to cancel this program at any time, and the decision to pay a bounty is entirely at our discretion. Your testing and submission must not violate any law or disrupt or compromise any data that is not your own. There may be additional restrictions on your ability to submit content or receive a bounty depending on your local laws.
Safe Harbor
Any activities conducted in accordance with the restrictions and guidelines outlined in this policy will be considered authorized conduct under the Computer Fraud and Abuse Act. If legal action is initiated by a third party against you and you have fully complied with this program, Silicon Labs will take steps to make it known, either to the public or to the court, that your actions were conducted in compliance with the Silicon Labs policy.
Thank you for helping keep Silicon Labs and our users safe!
Resources for Researchers to Use
| Reference Title | Link | Purpose |
|---|---|---|
| Community Link | https://community.silabs.com/s/ | Reference for technical support |
| Project Page for Users | https://community.silabs.com/s/all-blogs?language=en_US | Blogs for various projects and timelines |
| Ordering Kits | https://www.silabs.com/development-tools | How to order kits for testing |
Disclosure Statement for Products
Silicon Labs intends to provide customers with the latest and most accurate documentation about security-related concerns associated with our products. There are multiple methods for disclosing security-related updates, including:
- PCNs – Product Change Notifications
- Release Notes – Documents provided with the release of software
- Direct Customer Communication – Communication through Sales or Field Application Engineers
- Security Advisories – Technical summaries about a security issue and the recommended action for addressing it
Use of products by customers must follow the provided specifications for operation to ensure proper functionality. In the event of a reported security concern, Silicon Labs will analyze the details to assess the impact on Silicon Labs products or software, determine the associated technical cause, and provide an appropriate resolution and/or disclosure.
Silicon Labs reserves the right to adjust the (software/hardware) product if necessary for security or reliability reasons. Information sharing on vulnerabilities may take the form of release notes, PCNs, advisories, application notes, and/or FAQs.
Read details on the Terms & Conditions and product-specific disclaimer content. Requests for product-related content not readily on our website may be made through our authorized sales channel.