Your browser is not supported.
For the best experience, please access this site using the latest version of the following browsers:
By closing this window you acknowledge that your experience on this website may be degraded.
Product Security
- (PSIRT)
- Vulnerability Reporting
- Security Advisory
- PGP Key
Product Security Incident Response Team (PSIRT)
Honeywell Aerospace PSIRT’s mission is to safeguard the integrity and trust of Honeywell Aerospace products and services by proactively managing and responding to security vulnerabilities and incidents. We are committed to delivering industry-leading security solutions through vigilant threat detection, swift incident response, and collaborative efforts, ensuring the resilience of our products and the confidence of our customers. To achieve this, the PSIRT is dedicated to the following key objectives:
- Vulnerability Incident Response
- Proactive Threat Monitoring and Detection
- Rapid Incident Response
- Collaboration and Communication
- Continuous Improvement
- Customer Assurance and Transparency
Honeywell Aerospace is committed to providing appropriate resources to analyze, validate, and address all reported security concerns.
In accordance with industry practices, Honeywell Aerospace does not share findings from internal security testing or other types of security activities with external entities.
Reporting a Potential Security Vulnerability
Honeywell Aerospace welcomes reports from independent researchers, industry organizations, vendors, and customers. To find out more information on how to report a potential vulnerability, please visit Vulnerability Reporting.
Bug Bounty Program
Honeywell Aerospace does not participate in a bug bounty program or provide any monetary incentives for discovering vulnerabilities. It is important to note that any unauthorized scan of our services and production systems will be considered an attack.
Disclosure
Honeywell Aerospace is committed to ensuring that customers are notified promptly and effectively when security issues require communication. Most security updates will be published on our Security Notice site once patches or workarounds are available.
To protect the integrity and safety of our products and services, we do not disclose detailed vulnerability information, reproduction steps, exploit code, or proof‑of‑concept material.
Consistent with industry best practices, findings from internal security testing and other security activities are not shared with external parties. Any unauthorized scanning or probing of Honeywell Aerospace services or production systems will be treated as an attack.
Honeywell Aerospace assigns CVE IDs for validated vulnerabilities and prepares CVE Records using approved CNA tools. We work closely with internal teams and external reporters to ensure accuracy, and we publish CVE Records along with the appropriate advisories. Our process follows CNA program requirements and aligns with industry practices for coordinated, timely, and actionable vulnerability disclosure.
Coordinated Vulnerability Disclosure
Coordinated Vulnerability Disclosure (CVD) is indeed a crucial process in managing and mitigating vulnerabilities in hardware, software, and services. Honeywell Aerospace’s approach to CVD involves engaging with various stakeholders such as partners, vendors, researchers, and community coordinators to ensure that newly discovered vulnerabilities are disclosed in a controlled and coordinated manner. Multi-party coordination is essential because it helps in understanding the different parties' vulnerability disclosure policies, handling policies, and contractual agreements, which in turn fosters trusted communication and collaboration.
By increasing transparency between parties, vendors can better understand and manage the risks posed by vulnerabilities. This transparency also facilitates engagements with other parties, ensuring that everyone involved is on the same page. The primary aim of CVD is to provide timely and consistent guidance to all parties and customers, helping them protect themselves effectively.
Honeywell Aerospace follows a similar approach to CVD. They encourage independent reporters who discover vulnerabilities to contact them directly, allowing Honeywell to investigate and remediate the vulnerabilities before they are publicly disclosed. The Product Security Incident Response Team (PSIRT) coordinates with the reporter throughout the investigation and provides updates on progress. Once an update or mitigation information is publicly released, the reporter is welcome to discuss the vulnerability publicly.
This process not only helps in protecting customers but also ensures that public disclosures are coordinated appropriately, and reporters are acknowledged for their findings. If a reported vulnerability involves a vendor product, the PSIRT will notify the vendor directly, coordinate with the reporter, or engage a third-party coordination center.
For more information on CVD, please review the information provided in the following links:
Report a Vulnerability
Reporting Instructions
Honeywell Aerospace encourages all individuals who have discovered a vulnerability in our offerings to report these findings so they can be addressed. However, certain items are out of scope if the reporter is seeking credit or faster prioritization. If you’re reporting multiple vulnerabilities or vulnerabilities in multiple products feel free to include in one submission.
Out of Scope
- Vulnerabilities have already been discovered and published in a CVE Record.
- Vulnerabilities found in offerings that are no longer supported.
- Vulnerabilities identified in offerings for which Honeywell has advised consumers to use the latest version or upgrade.
If the vulnerability affects a product, service or solution, email PSIRT@honeywellaerospace.com, with the following instructions/details:
Please encrypt using Honeywell’s public PGP key and include the following:
- Product and version
- Description of the potential vulnerability
- Any special configuration required to reproduce the issue
- Step by step instructions to reproduce the issue
- Proof of concept or exploit code, if available
- Code Scan requires proof of exploitability
- Potential Impact
For all other security issues, email us at security@honeywellaerospace.com with the following instructions.
Please encrypt using Honeywell’s public PGP key and include the following:
- Website URL or location
- Type of vulnerability (XSS, Injection, etc.)
- Instructions to reproduce the vulnerability
- Proof of concept or exploit code, including how an attacker could exploit the vulnerability
- Potential impact
PGP Key
-----BEGIN PGP PUBLIC KEY BLOCK-----
mQINBGo8XV0BEADrDv6YoKfK/g+a1CUeznQA2QZop1EZ+epovnyZPbNtPNeP1znE
OVBO1SgrfNxeyYNdlHo7i/d2BZXWle4/e6WJPeg12Xj/w+3i86PRrWir8J41e4cB
83RpnI7uASnixrf0ZZzhO4prIYOVAEwi9uDI0EyRaykXYoEr64kajZ+hcgGA4xgn
k9W+vG+Grxa4CWf3QmFIkBmbsTK3qm9AnRwaa0nHXvJ7YdqT/HuPsnz5cfGh1Scj
8I4rf6s+5Mww6uNFrNJjk/HtdpbU4lGhTcAmSW0XGdzaTGclDDhDR2GGvjgubDP9
QI6xruHJx/0kR1HbH+fXQvJdTkyHpTsfwSYkIFtsPNykKXDTcEIO8aUDkGjIGZYU
/RV0J5CIPrEeLoexuNjo74C2swL/KCrsqO++XM7RFsnmul+HrNI91vh96vGVcBi6
CDu/XWkAuG7fGrbx0hLXqel0GYLb4jd+t01OjJ9wF9gPRnFfjwG+w3W/dqjice2C
RSEfbqrikXhNkK0jAb40Tblxjlzr3B5CNLH3AZBuAjGcS1+v4oTzdrA8YTeBJ8Nl
oVb3wLimNp6WWRbWgfEwWiqW5QHyJk8gxFM8QpPPivkfBCJ32L3cVyzRDTJwGefI
33PvdBaE/YuEpGoa+E/2vXeuHkwaBg+bDQHcDs+WlGg6Ak1bNPlUqrhZ7wARAQAB
tC5BZXJvc3BhY2UgUFNJUlQgPHBzaXJ0QGhvbmV5d2VsbGFlcm9zcGFjZS5jb20+
iQJUBBMBCAA+FiEEBy+IaVwMZCdD1TVJiHyRHa+7FL0FAmo8XV0CGwMFCQeGHtAF
CwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQiHyRHa+7FL0UWxAAmvgdhaLwRt8W
GEjk2P1ZU7FcnbPjFOxMj33l9U901H8VpRra1YhhLzmRSFZwV7yRj8ikpp56ekvr
oYwWBBD2odoZF4a0X+09ENtsLoT+KAx8sC/MQ9lnDjeZFFDpXdd/dZvXWEuT8o5l
0IFsg/01lLgWX1kNDPFcNTg7b6YMKDG6AwpSWLXz3ZEZJjg3lP3oF/B1gxUvV9tt
fL/oaMPDNzwt1p6dWwlvE3+j4gTvYnc5pqThDHECf/jGFBF4ytqEqgiyKviHtNhe
SS3lxJHkhX8AzOoyzBbLIqvJTYCv5gWPNIX6NmCrBTmVPsSKbGZl7MQ/3IMhv9vj
MBbR1s7wXwfRoSDuAc8G3v5FlTthp/5kByoFC5C/mQ0igyoJyUPNmW7ces6NWtfl
jWIoRGjvSMFJNDXXqmIry0Z2+SvIzZZ+vjCneXmDuOXX1kvFynioGl6Qn8RD2ifN
9URl98rc1lgqyWI9Y2bHsIX3NYXPgfnFOvYqAx01jUidwZIVFB2UwqLyePKRKl30
7DV+B443U3C5a4Oo0iedIz60jJWnjwdZzvsvQrrfYeD25wFf7S8hChM2c9WdAKNt
gQq+GJ8/K2l9AG/P8mMl7y6Wwdz/0rV602aGgioyhs8L5JqsAnkyJk+AQ5HcsPpR
IiSCHQDw1lAvZ+QHZw5nRY7Y+DRXt3K5Ag0EajxdXQEQAKLZPRIOrKeGJvjn+E9t
abDyW4DTpcCeU3tvOQKFZ6R42BK82INK1sGpx7mmlMKyrNylJDP7OX0IBLKoNI64
yd1whQBceXBmd5cZEC/44fUIA26m6Hpk8C/HN53cKuVFGYGfidLWXNGhDv8kJLNS
2E05EEMrSjMhZ2dZswpDShi1uKvWD3km0qw38F0hjx69aRfU4qQksOTkJXqFk4I5
9RCjoD3dj8Jy13vGoylcMoFYEq0uFO4egX8kqtIbsx0wn2XNDivLQxvojnJNOoCQ
2mATk4+SA1Qrnalq6i7P6lFCrs+pSgQiXCjSC63XbfdIpmu70iGaZYYdRZZq5Ica
9M8BghjtQOxzh2lLltqe3G3WLaU/gWuFphvIsfI3pJsmopIEhRriSC+28TXz2nCm
na+iyeg2UPw8QlGSb8M0+D1DWwXyjAQtRdhmfJbM9NQJbvWiFz7wxuwlB7bVmaX3
YfzJHgGVDd3xKQzrNbTTT0cwdWZJ8x4J87vlyllaZ6NQplbSnRoab+gHmx3OypRi
gu4P820VzTVgiNPQ4ziryCtqjw88WopjVsALB0MRY1/Ndo7prnACDKQASwB0D3AX
f/rvfCE4Y5mJVWn9ixNCZVqh1nCyaGIRolMhBN81JAOMilRQgGhkqV5PwLDH4+7n
BdKLqe5x7HX2+p/lLnWQ40LzABEBAAGJAjwEGAEIACYWIQQHL4hpXAxkJ0PVNUmI
fJEdr7sUvQUCajxdXQIbDAUJB4Ye0AAKCRCIfJEdr7sUvVqCEACinurphKStbH7K
KlPApbwArcrwxCEkOxn4QDIcdOJZn0ZRD8gzSFw68NBCo+BG5qcYZ5hIBIbMjTSX
l6W8Rgt9NC4Y64aO3eQst8TuRlzIG/cE6n7lLjnKdlmMxbel19oPpC/D9NFWUc5X
LbvrRz4Wl8s/l9KZSS5fry2GgJCkeELg04nIlrtA3sVDFLuLVwPu3J3fl+kJ5yiE
VQnXvXYkMTF1fubl2RpO5BuIJPVgqSuEOL5a/sunpFLWgs9lAyEEB3wNd8bqKp7b
x0MJCbGAYNPLwFWEdFPzpW9Sv9wrHSDWPVWBhdPgJc/IOAoh/JW0FiJKI9L+aZnl
r3GLQUE7h4xLM2rADxJ/f+IJGwn41XGQ1tdEoUMMnXSGV3PvGqvYbr0M8gPi6ETl
4VYqHp3orP0h+xZCzAEKhna55eG8Y1lP9lkMK1UAxHIa9bRSIKnjljqA8+HiSWVi
lRrkSS2WFkh1+AJTgecsGv5U4Cywt/ouA7H4Q60ffy/nQdSiVQYi85pQc+Nuz7tf
hViGYTWjxQaWDiO3lwzXynUcjR5hfxeESjaHCTbtaHjNeDVE7d4MDEmN17OQyJk9
bswYAMACxCuULEXwXHsCP0hqyMbzJ8ON84g4/pDq0/7XXUzYCNNev5EM0Q9sJo5G
mRseh487Uct1P/RFmuRJZ2BVPxr27g==
=O9qd
-----END PGP PUBLIC KEY BLOCK-----