Welcome to Elastocon’s security page. To ensure the safety of our products and to comply with the EU Cyber Resilience Act (CRA), we provide this central point of contact for security inquiries and vulnerability reporting.
Coordinated vulnerability disclosure (CVD) policy
Elastocon welcomes reports of security vulnerabilities from researchers, customers, and users. We follow a coordinated vulnerability disclosure process to ensure the security of our products throughout their lifecycle.
Reporting
Please report any security vulnerabilities to our dedicated contact point:
- Email: This email address is being protected from spambots. You need JavaScript enabled to view it.
What to include in your report:
- A brief description of the vulnerability and its potential impact.
- Steps to reproduce the issue (preferably with a proof-of-concept, screenshots, or log files if available).
- The affected product (including instrument model, serial number, and software/firmware version).
- Information about the operating system or environment in which the software is running.
Our commitment
- We will acknowledge receipt of your report within a reasonable timeframe, normally within 2 business days.
- We will analyse and prioritize the report according to our internal process.
- We will provide regular updates when a fix or mitigation is identified.
- We coordinate public disclosure with the reporter when applicable.
- We will not take legal action against reporters who act in good faith and follow this policy.
Support period and security updates
Elastocon provides free security updates for all products with digital elements (software and connected hardware) during the product support period.
- Support period: At least 5 years from the date the product is placed on the market (or as specified by customer agreement).
- Scope: This commitment applies strictly to security-related fixes and patches for identified vulnerabilities. It does not include new features, feature enhancements, or general software upgrades.
Security advisories
Information about fixed vulnerabilities (CVEs) and security patches is published here.
Active advisories:
- ELA-SA-2026-001 (June 17, 2026): DLL hijacking vulnerability in shared National Instruments components (CVE-2025-2629).