Imprint / Impressum and Legal notices

PLS Programmierbare Logik & Systeme GmbH
Technologiepark
Straße der Freundschaft 92
DE-02991 Lauta
Germany

Phone: +49 35722 384 - 0
E-Mail: info@pls-mc.com
Internet: www.pls-mc.com www.pls-mc.de

Legal form: Limited Liability Company (GmbH)
Registered office of the company/Registration Court: Local Court Dresden/ HRB 3345
VAT no.: DE 140766942

Managing Director
Thomas Bauch

Legal notices

Liability for content provided on this website

PLS Programmierbare Logik & Systeme GmbH (hereinafter: "PLS") has created the content of the sites operated by it with the utmost care. PLS assumes no guarantee for the correctness, completeness and up-to-date status of the content provided.
The general statutory liability rulings of the German Digital Services Act ("DDG") apply. Under these, service providers are responsible only for their own content on these sites pursuant to general laws. There is no obligation to check third-party content in terms of any legal violations (Section 5 DDG, Regulation (EU) 2022/2065).

An obligation to remove or block the use of information pursuant to general laws remains unaffected. In this context, liability for third-party content can only be considered from the time knowledge is gained of a specific violation of the law. If we become aware – in particular on the basis of information from third parties ("Notice") - of corresponding violations of the law, we shall remove this content without delay ("Take down").

Copyright and other Intellectual Property Rights

PLS claims copyright to the content provided on the own websites. The reproduction, editing, dissemination and any form of exploitation are prohibited, and require the written consent of the author on a case-by-case basis. The content has been created in part by third parties whose copyright must also be observed. Third-party content will be designated as such. This Section also applies to own and third-party trademarks and other intellectual property rights.

Liability for links

The websites provided by PLS contain links to external websites of third parties. PLS has no influence on the content of these external websites. Responsibility for the content of linked sites lies exclusively with the respective service provider. No continuous checking is carried out on the content of the linked sites. If we become aware - in particular through notification by third parties ("Notice") - of corresponding violations of the law, we shall remove/have removed the corresponding links/content without delay ("Take down").

Product Security & Vulnerability Reporting

If you have identified a potential security vulnerability affecting one of our products, please contact our Product Security Incident Response Team (PSIRT) using one of the contact methods below.

What to Report

Please use this contact channel for:

  • Suspected security vulnerabilities
  • Actively exploited vulnerabilities
  • Security configuration flaws
  • Authentication or authorization bypass issues
  • Cryptographic weaknesses
  • Supply chain security issues affecting our products

For general technical support, please contact our support team at support@pls-mc.com

What to Include in Your Report

To help us assess and address the issue efficiently, please include:

  • Product name, order number or at least the product's serial number
  • Installed software version (as shown in the Help > About UDE dialog)
  • A detailed description of the vulnerability
  • Steps to reproduce (if applicable)
  • Potential impact of the vulnerability
  • Proof of concept (if available)
  • Your contact information for follow-up questions (optional)

Reports must be submitted in English or German.

If you prefer encrypted communication, please contact us to obtain our S/MIME public certificate.

Anonymous Reporting Option

You may choose to provide your contact information or submit a report anonymously. Please note that if you submit a vulnerability report without contact details, our ability to assess, clarify, and effectively address the issue may be limited. In some cases, this may prevent us from fully investigating or resolving the reported issue.

Our Vulnerability Handling Process

Upon receiving your report, we will:

  • Acknowledge receipt without undue delay
  • Assess and triage the reported issue
  • Contact you, where possible, to request additional information or clarification
  • If the vulnerability is confirmed, develop and provide appropriate mitigations or security updates.
  • Where appropriate, coordinate the disclosure of confirmed vulnerabilities in accordance with Coordinated Vulnerability Disclosure (CVD) practices.

We handle all vulnerability reports in good faith and ask that security researchers act responsibly. In particular, they should not exploit vulnerabilities beyond what is reasonably necessary to demonstrate their existence or take actions that could negatively impact our customers, products, or services while verifying a suspected vulnerability.

Please note the following:

  • If a reporting person or entity does not respond to requests for technical or content-related clarification, our ability to process the report may be limited or, in some cases, prevented altogether.
  • Anonymous reports may be processed only to a limited extent because we may be unable to request additional information or clarification.
  • If you submit your report anonymously, we may be unable to acknowledge receipt, request additional information, or provide feedback on the outcome of our investigation.

Legal Notice

This page provides the designated Single Point of Contact (SPOC) for security-related communication under Article 13(17) of Regulation (EU) 2024/2847 (Cyber Resilience Act). This channel is intended exclusively for reporting security vulnerabilities affecting supported PLS products. It does not replace customer support or commercial communication channels.

Product Security Advisories

Our Product Security Advisories are available at: https://www.pls-mc.com/support/security-advisories/

Contact Information

You may contact our Product Security team using any of the methods below. To facilitate efficient handling of your report, please provide as much relevant information as possible.

Email

psirt@pls-mc.com

Postal address

PLS Programmierbare Logik & Systeme GmbH
Product Security Incident Response Team (PSIRT)
Technologiepark
Straße der Freundschaft 92
DE-02991 Lauta
Germany

We encourage responsible vulnerability disclosure and will handle all reports in a timely and confidential manner.