Vulnerability and Security Incident Reporting for Products with Digital Elements
The security of our products and services is a top priority for Ducati Energia S.p.A. and our customers. For this reason, we promote the responsible and coordinated management of vulnerabilities and security incidents, encouraging the reporting of potential issues and ensuring a transparent and secure process for their handling.
Anyone outside the company who identifies a potential vulnerability in Ducati Energia products or services should follow the official reporting procedure:
- Submit the report by email to:
- Provide sufficient information to enable an assessment of the issue, including:
- Reporter’s name and contact details (First Name, Last Name, Email, Telephone)
- Company details (Company Name, Country)
- Manufacturer, product code, and serial number of the affected product
- Software version and configuration
- Date and method by which the vulnerability was identified
- Technical description of the vulnerability
- Any proof of concept or test code (clearly marked as such)
- Risk assessment or evidence of exploitation of the vulnerability
- Logs, screenshots, configuration files, or other attachments useful for the analysis

