Motortronics UK takes product security seriously. If you believe you have identified a vulnerability in one of our products or associated digital services, please tell us promptly using the guidance below.
Responsible reporting helps us investigate, reduce risk and provide appropriate corrective information.
This covers Motortronics-branded product, including the VMX-synergy, VMX-agility and VMX-Synergy Plus ranges.
Describe what you found
A clear description of the suspected vulnerability and the security impact you believe it may have.
Roughly when it was first seen, and how it came to light. For example routine monitoring, an alarm, a site visit, commissioning, a penetration test or a report from someone else.
Step-by-step reproduction details, including necessary access level, network position, tools and preconditions.
Answer as best you can. “I don’t know” is a useful answer, as it tells us to check.
Whether any incident or loss of availability, integrity or confidentiality has occurred.
Identify the product
The affected product name, model, serial number and configuration.
Where the affected equipment is installed. If it is installed across more than one country, list them.
Communication options fitted, what network it is on, anything unusual about the installation.
Any other equipment connected to the same network as the affected unit, including makes and models where you have them. A complete system control wiring diagram is the most useful thing you can send us, if one is available.
Supporting evidence such as logs, screenshots or proof-of-concept information, with sensitive data removed where possible. A complete system control wiring diagram is particularly useful if you have one. Up to three files, 20MB in total. For anything encrypted or larger, use the email address above.
How we reach you
Your name, organisation and preferred contact details. Anonymous reports are accepted but contact details help us ask follow-up questions.
Do not include live credentials, personal data or harmful payloads unless we request a secure transfer. Please avoid sending personal data, passwords, private keys, customer-confidential information or export-controlled material unless specifically requested through a secure channel.