Ferrari logo
  • Collections
Ferrari logo
    Responsible Disclosure Programme

    1. What is Responsible Disclosure in Ferrari

    Responsible Disclosure is an ethical method to report system vulnerabilities in our ICT system, which allows us sufficient time to identify and apply the appropriate countermeasures before these vulnerabilities might become public.

    By following this method, the sender helps us to identify and resolve system flaws, thus providing a valuable and efficient contribution to increase the security of ICT services and customers data and avoiding damage or disruption to our systems.

    2. How Responsible Disclosure works in Ferrari

    Should customers, researchers or experts identify one or more vulnerabilities in any of the following environments:

    • Ferrari portals (e.g.. www.ferrari.com, etc.)
    • Mobile applications bearing the Ferrari logo and published on official stores
    • Other technological instrument or IT services in use or provided by Ferrari

    they can send the information to Ferrari following the procedure laid out below.

    The reporting person must avoid performing any activity that can either disrupt the impacted system or service or cause any data leakage/loss, limiting his/her use of the system/service to the minimum necessary and refraining from accessing data not strictly necessary to prove the existence of the vulnerability.

    3. Reporting a vulnerability responsibly

    Specifically, whoever activates the procedure must send the information via email to responsible_disclosure@ferrari.com. Please include the following technical information:

    • Type of vulnerability or issue
    • Service, product or URL affected
    • IP address from which the vulnerability was identified, together with the date and time of discovery
    • Special configuration or requirements to reproduce the issue
    • Information necessary to reproduce the issue
    • Confirmation that no activity has been performed to disrupt our system or services and that no data has been copy or taken
    • The consensus or not to being listed in the Hall of Fame section, together with an optional personal contact and personal photo, if you want it to be mentioned alongside your Name and Surname.

    Please observe strict secrecy on all information pertaining to the vulnerabilities discovered, and therefore commit not to reveal any of these, entirely or partially, or in any form make them available to third parties without Ferrari authorization.


    Once a notice has been received, Ferrari is committed to following up as follows:

    1. Send an email to the reporting person/entity to acknowledge reception of the mail with the information outlined above. Within 10 days from this confirmation, Ferrari will send a second email with an evaluation of the relevance of the vulnerability and the results of an initial analysis.
    2. Adequately manage the vulnerability report to respect the timeline indicated previously
    3. in case of an eligible report , upon explicit authorization of the reporting person publicly thank the sender in the Hall of Fame section if the necessary authorization accompanied the original mail.


    Below you will find some examples of vulnerability categories, which are considered eligible for publication in the Hall of Fame:

    • Cross Site Scripting (XSS)
    • Cross Site Request Forgery (CSRF)
    • Injection (i.e. SQL injection, user input)
    • Broken Authentication and Session Management
    • Broken Access Control
    • Security Misconfiguration
    • Redirect / Man in the Middle attacks
    • Remote code execution
    • Underprotected API
    • Privilege Escalation


    On the other hand, the following situations are not covered by this Responsible Disclosure initiative and therefore are not eligible for the Hall of Fame:

    • Situations that are not inherent to security aspects (i.e. unavailability of a service, non-security bugs in a GUI, etc.) and therefore managed through traditional channels of customer care.
    • Problems regarding phishing or spam and vulnerabilities inherent to social engineering techniques; these must be signaled either via email to abuse@ferrari.com. If the original email contains a suspicious attachment, please make sure that it is not included in your message, as this will like cause your email to be blocked.
    • Results of automatic tools for vulnerability assessment/penetration testing (i.e. Nessus, nmap, …).
    • Reports on the use of weak configurations of the TLS protocol, or reports on non-compliance with best practices such as, for example, the lack of security headers.


    While carrying out your activities please respect the following rules:

    • report the vulnerability to us in the manner set out above;
    • report the vulnerability as soon as you can to prevent that threat actors exploit the vulnerability before we have a chance to fix it;
    • report the vulnerability with us while keeping the information confidential (in particular if it concerns personal data);
    • do not use social engineering or phishing to gain access to our IT infrastructure or services;
    • do not install your own backdoor or execute code in our systems to disclose the vulnerability as this may result in unnecessary damage and security risks;
    • do not exploit a vulnerability beyond what’s necessary to confirm the vulnerability;
    • do not modify the system/service or data in any manner;
    • do not use Denial of Service attacks, aggressive and/or automated scanning or brute force access technology;
    • do not negatively impact the confidentiality, integrity or availability of our services or our data;
    • Certain hacking activities constitute criminal actions. To protect you and us please act in good faith and follow these rules of ethical engagement
    4. Hall of fame

    We would like to thank all persons who make a responsible disclosure to us and recognize their valuable contribution in increasing the security of our products and services for our benefit and for the benefit of our customers by featuring those contributors in our hall of fame.

    Go to the Hall of fame

    Ferrari reserves the right to update this Responsible Disclosure programme at any time.


    If at any time you have questions about this programme, feel free to reach out to responsible_disclosure@ferrari.com


    This programme is based on guidance issued in 2022 by Enisa, available here:

    Coordinated Vulnerability Disclosure policies in the EU
    Good practice guide on vulnerability disclosure
    Auto
    • Ferrari Line Up
    • Ferrari Car Configurator
    • Personalization
    • Services
    • Officine Classiche
    • Driving Courses
    • Ferrari Certified Pre-owned
    • Ferrari Dealer locator
    • MyFerrari App
    • Recall information
    • TechInfo
    • Financial Services
    Scuderia Ferrari
    • SF-23
    • Charles Leclerc
    • Carlos Sainz
    • News
    • Media Galleries
    • Races
    • Scuderia Ferrari History
    • Ferrari Driver Academy
    • Partners
    • Ferrari F1 Club
    • Scuderia Ferrari Member
    • Scuderia Ferrari Club Locator
    Collections
    • Man
    • Woman
    • Kids
    • Ferrari Watches
    • Ferrari Shoes
    • Scuderia Ferrari Replica
    • Ray-Ban Eyewear
    • Ferrari Memorabilia
    • Ferrari Store Locator
    Races
    • Competizioni GT
    • Corse Clienti
    • Ferrari Challenge
    • XX Programme
    • F1 Clienti
    • Club Competizioni GT
    Universe
    • News
    • The Official Ferrari Magazine
    • Ferrari Museums
    • Ristorante Cavallino
    • History
    • Ferrari Simulation Center
    • Ferrari World Abu Dhabi
    • Ferrari Land Barcelona
    FacebookFacebook
    • Ferrari Official
    • Scuderia Ferrari
    • Ferrari Races
    • FDA
    • Ferrari Esports
    • Ferrari Style
    • Musei Ferrari
    • Ristorante Cavallino
    InstagramInstagram
    • Ferrari Official
    • Scuderia Ferrari
    • Ferrari Races
    • Ferrari Hypercar
    • Ferrari Driver Academy
    • Ferrari Esports
    • Ferrari Style
    • Musei Ferrari
    • Ristorante Cavallino
    LinkedinLinkedin
    • Ferrari Official
    • Scuderia Ferrari
    Tik TokTik Tok
    • Ferrari
    TwitchTwitch
    • Ferrari Esports
    TwitterTwitter
    • Ferrari Official
    • Scuderia Ferrari
    • Ferrari Races
    • Ferrari Hypercar
    • Ferrari Driver Academy
    • Ferrari Esports
    • Ferrari Style
    • Musei Ferrari
    YouTubeYouTube
    • Ferrari Official
    Ferrari
    Ferrari N.V. - Holding company - A company under Dutch law, having its official seat in Amsterdam, the Netherlands and its corporate address at Via Abetone Inferiore No. 4, I-41053 Maranello (MO), Italy, registered with the Dutch trade register under number 64060977

    Ferrari S.p.A. - A company under Italian law, having its registered office at Via Emilia Est No. 1163, Modena, Italy, Companies’ Register of Modena, VAT and Tax number 00159560366 and share capital of Euro 20,260,000

    Copyright 2023 - All rights reserved
    • Legal
    • Privacy Policy
    • Cookie Policy
    • Submit your privacy request
    • Contacts
    • Media Centre
    • Career
    • Corporate ENG
    • Corporate ITA
    • Responsible Disclosure
    International
    Logo partner