Description

SBB operates Switzerland's national railway network, providing passenger and freight transportation services. Welcome to our public Bug Bounty program. We are specifically looking for: * Leaking PII Data (customer) * Data manipulation High performance researcher may be invited to our private programs!

Bounties
Low
0.1 - 3.9
Medium
4.0 - 6.9
High
7.0 - 8.9
Critical
9.0 - 9.4
Exceptional
9.5 - 10.0
Tier 1
100
500
750
2,000
5,000
Tier 1
€100 - €5,000
Tier 2
25
125
400
1,000
2,500
Tier 2
€25 - €2,500
Tier 3
25
100
200
400
800
Tier 3
€25 - €800
Rules of engagement
Required
Not applicable
max. 5 requests /sec
Not applicable

Our promise to you

  • We will respond to reports in ultimately two weeks, probably faster!
  • We are happy to respond to any questions, please use the button in the right top corner for this.
  • We respect the safe harbour clause that you can find below

Your promise to us

  • Provide detailed but to-the point reproduction steps* Include a clear attack scenario. How will this affect us exactly?
  • Remember: quality over quantity!
  • Please do not discuss or post vulnerabilities without our consent (including PoC's on YouTube and Vimeo)
  • Please do not use automatic scanners -be creative and do it yourself! We cannot accept any submissions found by using automatic scanners. Scanners also won't improve your skills, and can cause a high server load (we'd like to put our time in thanking researchers rather than blocking their IP's 😉)

Conditions of participation

  • SBB employees (including former employees that separated from SBB within the prior 12 months), contingent workers, contractors and their personnel, and consultants are excluded from any payment
  • You may not participate in this program if you are a resident or individual located within a country appearing on any U.S. sanctions lists (such as the lists administered by the US Department of the Treasury’s OFAC).

The researcher guidelines from Intigriti apply in full with the following modifications and additions:

  • SBB reserves the right to change the terms of their Bug Bounty programs at any time and reserves the right to cancel all programs at any time.
  • The relationship between you and SBB is governed by and construed in accordance with the laws of Switzerland. Sole place of jurisdictions are the courts in Bern.
  • You acknowledge and agree that you shall not use your relationship with SBB for any marketing or financing purpose or as reference in any personal or professional presentation, documentation or other material, or in any way utilize (neither on the Internet nor in any other way communicate to the public) any trade name, business name, logotype or trademark of SBB.
Domains

Mobile Apps

Tier 1
Other

SBB Mobile - your personal travel companion for public transport.
SBB Mobile IOS | SBB Mobile Android

SBB Preview - always be among the first to test the latest features.
SBB Preview IOS | SBB Preview Android

Backend URLs
*.sbbmobile.ch

Please find more details about the apps in the
FAQ for SBB Mobile and SBB Preview

*.swisspass.ch

Tier 1
Wildcard

Swisspass is the key to mobility in Switzerland.

With SwissPass customers can manage their travelcard details easily and use the partner services.

URL

*.sbb.ch

Tier 2
Wildcard

Mobile Apps

Other

SBB Freesurf - browse the web for free on the train.
SBB Freesurf IOS | SBB Freesurf Android

SBB GO - as a study paricipant, you can record your customer journey with the SBB go app and evaluate SBB Touchpoints along your journey.
SBB GO IOS | SBB GO Android

SBB Inclusive - provides visual and digital customer information in stations and on SBB long-distance services
SBB Inclusive IOS | SBB Inclusive Android

SBB P-Rail - your parking space at the station
P+Rail IOS | P+Rail Android

Severity assessment

To reward your efforts we are using Intigriti's Contextual CVSS.

FAQ

How do I get credentials?

For applications in our public program, we do not provide any credentials, please feel free to register yourself where possible (with your intigriti.me email address).
Exception: Existing SwissPass users may use their personal accounts on their own risks.

All aboard!
Please log in or sign up on the platform

For obvious reasons we can only allow submissions or applications for our program with a valid Intigriti account.

It will only take 2 minutes to create a new one or even less to log in with an existing account, so don't hesitate and let's get started. We would be thrilled to have you as part of our community.