Description

The BMW Group is the world's leading provider of premium cars and motorcycles and the home of the BMW, MINI, Rolls-Royce and BMW Motorrad brands. Our vehicles and products are tailored to the needs of our customers and constantly enhanced. We place special emphasis on the security, integrity and availability of our data and systems and thus also on those of our customers, employees and partners.

Bounties
Low
0.1 - 3.9
Medium
4.0 - 6.9
High
7.0 - 8.9
Critical
9.0 - 9.4
Exceptional
9.5 - 10.0
Tier 1
250
500
1,500
3,500
6,000
Tier 1
€250 - €6,000
Tier 2
150
300
1,000
2,000
3,000
Tier 2
€150 - €3,000
Rules of engagement
Required
Not applicable
max. 2 requests /sec
X-Intigriti-Username: {Username}

Policies

By participating in this program, you agree to:

  • Respect the Community Code of Conduct
  • Respect the Intigriti Terms and Conditions
  • Respect the scope of the program
  • Do not discuss or disclose vulnerability information without prior written consent (including PoC's on YouTube, Vimeo and other video platforms)

General Rules

  • Employees and former employees or contract partners of BMW, its subsidiaries and associated companies, as well as their relatives or household members, are excluded from participation. The exclusion can also be carried out retrospectively and in this case a bounty or bonus can be reclaimed.
  • Multiple vulnerabilities caused by one underlying issue will be awarded one bounty
  • Some sites might rely on shared resources or assets. If we identify this issue, we will only award a bounty for the first report
  • We will not reimburse you for any costs related to proof of concepts (or else) created by the researcher
  • We will not provide any test accounts

Dos and Don'ts

Dos

  • Always submit proof (e.g., a PoC) regarding the exploitability of your finding
  • Provide a detailed report with all necessary, reproducible steps, including the full http requests leading to the exploit
  • Only submit one vulnerability per report, unless you need to chain the vulnerabilities for successful exploitation
  • Set the request headers according to Intigriti’s guidelines
  • Adhere to the rate limitations according to Intigriti’s guidelines

Don'ts

  • Do not disclose details of this program or vulnerabilities (even resolved ones) to the public or any third party without the explicit consent of the BMW Group
  • Do not perform any testing that causes degradation to BMW's services e.g., denial of service, or heavy automated scanning
  • Do not access or make changes to customer accounts
  • Do not perform social engineering attacks, including phishing
  • Do not spam
  • Do not perform any physical attacks
  • Do not perform any lateral movement or post-exploitation past the initial exploitation

Validation times

Are currently undergoing re-evaluation.
Please note that No bounty findings may take significantly longer to validate.

Check our fix

We offer up to €50 bonus to verify a resolved issue for us (when requested).
This remains at the discretion of the BMW Group to award.

Domains
URL
URL

Other BMW Domains

No bounty
Other

Please select this asset to report vulnerabilities affecting BMW assets but not matching any of the assets stated above.

Important: Note our policy regarding "No Bounty Domains" and a potentially deviating application of the safe harbor clause.
We may award a small bonus for these assets, but only valid high, critical and exceptional severity findings - this is however, at the discretion of the BMW Group team.

Automotive Security

Out of scope
Other

Please submit valid findings regarding Automotive assets in our public BMW Group - Automotive program.

Domains from independent BMW Dealers, Resellers or Fanclubs

Other

These domains belong to legally independent entities. We can only inform these entities. However, we have no influence on the mitigation process of the vulnerabilities in these assets.

Severity assessment

This program follows Intigriti's contextual CVSS standard

FAQ

Where can I get test credentials?

We currently don’t offer any credentials to test user roles.

I believe I have found a vulnerable asset related to BMW but I am not sure if the asset actually belongs to BMW. Can I still report it?

Yes! If you are unsure if the vulnerable asset you found belongs to BMW and you believe that it is not owned by an independent retailer, importer, service provider, fan club, etc. please use the "Other BMW Domains" asset to report this vulnerability. Note that these assets are not eligible for bounty but we may award a bonus for high, critical and exceptional severity findings.

All aboard!
Please log in or sign up on the platform

For obvious reasons we can only allow submissions or applications for our program with a valid Intigriti account.

It will only take 2 minutes to create a new one or even less to log in with an existing account, so don't hesitate and let's get started. We would be thrilled to have you as part of our community.