KÄRCHER PRODUCT AND SERVICE SECURITY REPORTING AND ADVISORIES

Mitarbeiter am Computer

Vulnerability Reporting and Coordinated Vulnerability Disclosure Policy

As of: 10.09.2026

Preamble

This Coordinated Vulnerability Disclosure Policy defines how Alfred Kärcher SE & Co. KG (hereinafter referred to as "Kärcher" or "we") handles vulnerabilities in products with digital elements manufactured by Kärcher.

"Product with digital elements" means any software or hardware product and its remote data processing solutions, including software or hardware components, placed on the market separately, whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network.

"Vulnerability" means a weakness, susceptibility, or malfunction of a product with digital elements that can be exploited by a cyber threat. "Cyber threat" means any potential circumstance, event, or action that could damage, disrupt, or otherwise adversely affect products with digital elements, users of such products with digital elements, or other persons.

1. Values and Principles

Cybersecurity meaning the protection of products with digital elements, the protection of users of such products, and the protection of other persons against cyber threats is of paramount importance for our products with digital elements. We follow a security-by-design approach and are committed to keeping our products with digital elements secure throughout their entire lifecycle. Therefore, Kärcher aims to collaborate closely with the cybersecurity community. We encourage researchers, authorities, business partners, and other private and public actors (hereinafter "Reporter" or "you") to contact us regarding vulnerabilities in our products with digital elements (a "Vulnerability Report"). Such third-party security information forms a valuable part of our security architecture.

 

2. Reporting and Disclosure Conditions

Kärcher aims to make communication with Reporters as simple and accessible as possible. We ask you to observe the following:

 

2.1 General Provisions:

  • Vulnerability Reports can be submitted in English and German.
  • Kärcher will treat Vulnerability Reports confidentially to the extent permitted by law. Information required for the disclosure of the vulnerability, as well as Kärcher affiliated companies, are expressly exempted from this requirement. A separate non-disclosure agreement is not required.
  • Kärcher will not disclose personal data of Reporters to third parties without their consent. This does not apply to disclosures to Kärcher affiliated companies.
  • Vulnerability Reports must relate to a Kärcher product with digital elements, i.e., the product bears the Kärcher logo.

Kärcher will not pursue legal action (whether civil or criminal) in connection with Vulnerability Reports, provided that:

  • The Reporter acts in good faith within the scope of this policy and pursues no criminal intent;
  • The Reporter causes no harm to Kärcher and/or its affiliated companies, customers, suppliers, or partners;
  • The Reporter does not compromise the privacy or security of Kärcher and/or its affiliated companies, customers, suppliers, or partners, nor the operation of Kärcher's services;
  • The Reporter agrees not to publish their findings until Kärcher has been able to remediate the vulnerability in accordance with the timelines set out in Section 2.3;
  • The Reporter’s actions do not violate any law; and
  • The Reporter’s actions do not disrupt or compromise third-party data or confidential information.

 

2.2 Recommended Content for a Vulnerability Report

Where known, we recommend providing the following information in a Vulnerability Report:

  • Name of the affected IoT product or digital service (preferably including model name, serial number, domain name, or URL)
  • Contact information of the Reporter for further communication (identifiable or anonymous)
  • Description of the impact, findings, or vulnerabilities (if possible, with logs, images, or other supplementary material to reproduce the finding)
  • ID, identifier, or category of the vulnerability or report subject (if possible, based on CWE or OWASP)
  • If known: impacts, dependencies, or other influences of the report subject
  • If known: CVSS3 score or an estimation of CVSS-like parameters (e.g., required privileges, required user interaction, availability of exploit tools, etc.)
  • If known: awareness or prevalence of the vulnerability or exploit.

We will process every Vulnerability Report in accordance with the process described below. The more information we receive, the better we can respond to the Vulnerability Report. If we do not receive sufficient information, we may place the report on hold or decide not to pursue it further.

 

2.3 Disclosure Process

Vulnerability Reports are processed by us as follows:

  • We inspect every Vulnerability Report immediately upon receipt for indications of actively exploited vulnerabilities.
  • We verify whether the Vulnerability Report falls within the scope of this policy.
  • We send an initial response within three business days (Monday to Friday).
  • Within 3 business days of receiving the Vulnerability Report, we respond with an initial analysis or further inquiries.
  • After 10 business days at the latest, we send detailed feedback, which may include: a confirmation or rejection of the reported vulnerability, further questions regarding the facts, or an explanation of why the investigation/remediation of the vulnerability is still ongoing.

Kärcher will publicly disclose validated and verified vulnerabilities within 90 days, unless Kärcher identifies the vulnerability and remediates it before the affected product is placed on the market. In justified exceptional cases, this deadline may be extended once for an additional 90 days in close coordination with Kärcher’s competent national CSIRT. Furthermore, under exceptional circumstances, the period prior to public disclosure may be extended further by the competent national CSIRT upon application by Kärcher.

Public disclosure takes place in the European Vulnerability Database (EUVD) maintained by ENISA.

The process is deemed completed when:

  • The Vulnerability Report is unfounded or falls outside the scope of this policy;
  • The vulnerability has been remediated and publicly disclosed;
  • The Reporter fails to respond to inquiries from Kärcher for at least 30 days, or further inquiries are not possible and the information contained in the Vulnerability Report is insufficient to reproduce or verify the vulnerability; or
  • In agreement with the competent CSIRT, it is established that the vulnerability cannot be remediated, and the disclosure of the vulnerability has taken place.

Throughout the entire process, the following applies:

  • Vulnerability remediation is performed as quickly as possible.
  • Final feedback and security measures depend on the complexity of the respective individual case.
  • We keep the Reporter informed of progress and notify them as soon as the vulnerability has been remediated. This does not apply to anonymously submitted Vulnerability Reports.
  • In the event of actively exploited vulnerabilities and severe security incidents that impact the security of the product with digital elements and of which Kärcher becomes aware, Kärcher will notify the competent CSIRT and ENISA within the legally mandated deadlines and provide information on all new developments and measures.

 

3. Handling Inquiries Outside the Scope of this Coordinated Vulnerability Disclosure Policy

Inquiries that do not fall under this policy cannot be processed through this single point of contact. We will inform you if your Vulnerability Report falls outside the scope of this policy. In such cases, please contact customer service, your designated sales representative, or your dealer.

 

4. Rights of Use

Kärcher values every Vulnerability Report and aims, wherever possible, to implement proposed solutions for security issues. To appropriately utilize the Vulnerability Report as well as code, snippets, images, or other sources containing potential existing intellectual property, we require the rights of use listed below. Otherwise, security updates and patches cannot be provided, even if they resolve the security issue.

All rights to the Vulnerability Report remain with the Reporter. However, by submitting a Vulnerability Report to Kärcher, you agree to the following:

You grant Kärcher a non-exclusive, irrevocable, perpetual, royalty-free, worldwide, and sublicensable right of use regarding the intellectual property, know-how, or similar content contained in the Vulnerability Report for the following purposes:

  • To use, review, evaluate, test, and otherwise analyze the Vulnerability Report;
  • To reproduce, modify, distribute, publicly display, market, and create derivative works from the Vulnerability Report and/or its contents, in whole or in part;
  • You agree, if necessary, to sign any documents required to confirm the rights granted by you above;
    You understand and acknowledge that Kärcher may have developed or commissioned material that is similar or identical to your Vulnerability Report, and you waive any claims that may arise from similarities to your Vulnerability Report;
  • You understand and acknowledge that no compensation will be paid to you and that Kärcher is under no obligation to mention you by name (e.g., within the context of a bug bounty program); and
  • You confirm that your Vulnerability Report originates from you, that you have not used third-party information, and that you are authorized to submit the Vulnerability Report to Kärcher.

 

5. Contact Options

If you have discovered a potential vulnerability in one of our products or services, please report it to us via our central point of contact using the options below.

Good communication is essential for Vulnerability Reports and coordinated vulnerability disclosure. Therefore, we encourage you to provide at least one contact method, preferably an email address.

In the case of an anonymous report via our contact form, we cannot make follow-up inquiries. This may result in the Vulnerability Report being processed only to a limited extent or not at all. Furthermore, we will not be able to provide updates or feedback within the scope of this policy. 

You can reach Kärcher's central point of contact as follows:

 

Email: psirt@karcher.com

Our contact form, which also allows for anonymous reporting, can be found here:

Note: Please use PC or Tablet to access and fill out the refund form. The usage of the mobile version or the Internet Explorer might lead to errors in the display. We apologize for this.