Description

Welcome to Salto's responsible vulnerability disclosure program. Here you can report any finding which does not fit into any of our other bug bounty programmes on Intigriti. Salto is a global leader in electronic access control. We design, develop, and manufacture hardware and software for access control systems covering a wide range of uses. Salto locks are installed in all types of buildings, single family housing, hotels, university buildings and dorms, marine applications, critical infrastructure, and many other types of locations. As an access control company security is fundamental to everything we build. We take all reports seriously and strive to always give reports fair triaging. As this is a VDP, bounties are not guaranteed, but we may award compensation at our discretion depending on the nature and impact of the finding. Thank you for helping us make access control more secure. You can learn more about us on our website https://saltosystems.com/

Bounties

This is a responsible disclosure program without bounties.

While we do not offer bounties for reported vulnerabilities, we deeply appreciate your contribution to securing our assets.

If a vulnerability falls within the scope of one of our bug bounty programs assets but was handled in this program for any reason, we will provide a bonus equivalent to the bounty amount, ensuring fair compensation for your efforts. For other assets we may pay out a bounty depending on the severity of the finding and the quality of the report.

Rules of engagement
Required
Not applicable
max. 3 requests /sec
Not applicable

By participating in this program, you agree to:

  • Respect the Community Code of Conduct
  • Respect the Intigriti Terms and Conditions
  • Respect the scope of the program
  • Not discuss or disclose vulnerability information without prior written consent (including PoC's on YouTube and Vimeo)

Our promise to you

  • If you need any assistance or have questions related to our products take a look at our support page https://support.saltosystems.com/ or feel free to ask us a question
  • We aim to validate all submissions within 5 working days.

Your promise to us

  • Make a good faith effort to avoid any privacy violations, data destruction or degradation of our services
  • Do not post or discuss vulnerabilities without our consent, remember to upload any evidence such as pictures or recordings in accordance with this
  • Include a clear attack scenario, we need to know how an issue will potentially affects us. The clearer the better and we appreciate any mitigation suggestions
Assets
*.baeder-suite.de
Wildcard
Tier 2
*.cognitec.com
Wildcard
Tier 2
*.cognitec-systems.de
Wildcard
Tier 2
*.danalock.com
Wildcard
Tier 2
*.danalock.dk
Wildcard
Tier 2
*.danalock.eu
Wildcard
Tier 2
*.dejoris.de
Wildcard
Tier 2
*.envisio.io
Wildcard
Tier 2
*.enviso.shop
Wildcard
Tier 2
*.gantner.be
Wildcard
Tier 2
*.gantner.com
Wildcard
Tier 2
*.gantnercloud.com
Wildcard
Tier 2
*.gantnerindia.com
Wildcard
Tier 2
*.guidemylock.dk
Wildcard
Tier 2
*.my-clay.com
Wildcard
Tier 2
*.mylock.dk
Wildcard
Tier 2
*.mysmartlock.com
Wildcard
Tier 2
*poly-control.com
Wildcard
Tier 2
*.polycontrol.dk
Wildcard
Tier 2
*.poly-control.dk
Wildcard
Tier 2
*.poly-lock.dk
Wildcard
Tier 2
*.recreatex.be
Wildcard
Tier 2
*.saltoapis.com
Wildcard
Tier 2
*.saltoks.com
Wildcard
Tier 2
*.salto-orion.app
Wildcard
Tier 2
*.saltosystems.com
Wildcard
Tier 2
*.saltowecosystem.com
Wildcard
Tier 2
*.vintia.cloud
Wildcard
Tier 2
*.vintia.com
Wildcard
Tier 2
*.wecosystem.com
Wildcard
Tier 2
In scope

Our goal is to secure software, after all our customers trust us to secure their physical environment! We think we've done a pretty good job but we know that no implementation is perfect, we hope that you can help us spot the imperfections.

Please let us know prior to submission if you believe you've identified a vulnerability in a domain or asset belonging to Salto but which is missing from the in scope domains.

Anything related to the following scenarios would be considered extra interesting for us:

  • Unauthorised lock openings, or escalating/changing access rights to locks without having the permissions to do so;
  • Accessing data belonging to other sites (a site is typically representing a physical building/ lock installation) without permissions to do so;
  • Deleting or obfuscating event logs;
  • Remote code execution.

Having said that remember that our products are used to secure physical locations like the front door of your home. If you can think of a scenario that would make you very uncomfortable with having one of our products mounted to your front door then that is probably a pretty good angle of attack.

Out of scope

Any subdomain which is part of our bug bounty programs are out of scope for this vulnerability disclosure program, please submit them in our bug bounty programs instead. If you are unsure which program a submission belongs to you can reach us using bugbounty@saltosystems.com.

Asset out of scope Associated program
https://staging.api.danalock.com Salto HomeSolutions
https://danalock.com/ Salto HomeSolutions
https://staging.airbnb.danalock.com/login Salto HomeSolutions
https://api.danalock.com/swagger/index.html Salto HomeSolutions
Danalock Android/iOS mobile applications Salto HomeSolutions
https://api.staging-enviso.io/*/ Envisio Ticketing
www.enviso.io Envisio Ticketing
https://identity-acc.eu.my-clay.com Salto CloudWorks
https://intigriti-accept.saltoks.com Salto CloudWorks
https://clp-accept-user.saltoks.com Salto CloudWorks
https://indoor-acc.xs4com.app/ Salto CloudWorks
https://outdoor-acc.xs4com.app/ Salto CloudWorks
https://api-acc.eu.xs4com.app/ Salto CloudWorks
https://commissioning-accept.saltoks.com/ Salto CloudWorks
https://commissioningapi-accept.saltoks.com/ Salto CloudWorks
https://support-accept.saltoks.com Salto CloudWorks
https://clp-accept-larry.my-clay.com/ Salto CloudWorks
https://saltocloudworks.com/ Salto CloudWorks
XS4 Com mobile application Salto CloudWorks
Salto KS mobile application Salto CloudWorks

We require that all researchers take into account the respect for the law. Do not use social engineering or similar to achieve an exploit. Do not access more than is needed to demonstrate your exploit.

Example of out of scope actions:

  • Using social engineering
  • Compromising the system and persistently maintaining access to it
  • Changing the data accessed by exploiting the vulnerability
  • Using malware
  • Using the vulnerability in any way beyond proving its existence. To demonstrate that the vulnerability exists, the reporter could use non-intrusive methods. For example, listing a system directory
  • Using brute force to gain access to systems
  • Sharing vulnerability with third parties
  • Performing DoS or DDoS attacks

Keep information about any vulnerabilities you’ve discovered confidential between yourself and Salto Systems until we resolve the issue.

Severity assessment

This program follows Intigriti's triage standards based on the proof of concept.

FAQ

Where can I get credentials for your applications?

Please visit our other bug bounty programs to gain access to bug bounty assets. Assets which are not included in our other programs are generally out of scope for researcher invites but you can send an email to bugbounty@saltosystems.com and request access if you believe you've found an exceptional issue.

I believe I've found something which demands urgent attention.

Please send us an email at securityalert@saltosystems.com and include the Intigriti submission ID or details of your finding.

All aboard!
Please log in or sign up on the platform

For obvious reasons we can only allow submissions or applications for our program with a valid Intigriti account.

It will only take 2 minutes to create a new one or even less to log in with an existing account, so don't hesitate and let's get started. We would be thrilled to have you as part of our community.

Activity
8/3
Salto Wecosystem updated the confidentiality level to public
8/3
Salto Wecosystem updated the confidentiality level to registered
8/3
Salto Wecosystem updated the confidentiality level to application
8/3
Salto Vulnerability Disclosure
launched