Coordinated Vulnerability Disclosure Policy (VDP)

1. Purpose

Altice Labs is committed to ensuring the security, integrity, and resilience of its products and services.

This Coordinated Vulnerability Disclosure Policy (VDP) establishes the process through which security researchers, customers, partners, and other interested parties may report vulnerabilities identified in products developed, distributed, or maintained by Altice Labs.

2. Scope

This Policy applies exclusively to products, software, and services developed, distributed, or maintained by Altice Labs (Products – Altice Labs). Any other Altice Labs-owned or hosted assets, including domains, subdomains, applications, systems, and infrastructure, are out of scope and shall be subject to the procedures set forth in Section 9 of the MEO Information Security Policy.

3. Reporting Channel

Researchers can submit an initial report through the form available at www.alticelabs.com/vdp-submit. Once a report is received, all further communication regarding the disclosure will be conducted via the email address provided in the automated acknowledgment.

The report includes the following items. The mandatory ones are marked with an asterisk:

  • Affected product*
  • Device model
  • Firmware and/or software version*
  • Description of the vulnerability*
  • Expected impact*
  • Steps to reproduce and/or Proof of Concept (PoC)*
  • Technical evidence.

Altice Labs reserves the right to reject any report if sufficient technical evidence is not provided to demonstrate a relevant security impact on the products covered by this policy.

Researchers are responsible for the accuracy, consistency, and quality of the information submitted, including the validation of all evidence, analyses, and conclusions provided. The use of automation or Artificial Intelligence tools to support research and report writing is permitted and encouraged. However, Altice Labs reserves the right to disregard reports that show signs of lacking proper technical validation or human review.

4. Guidelines for Researchers

Altice Labs will not provide services, credentials, or hardware to external researchers. Researchers may conduct testing using their own equipment or on any in-scope products to which they have legitimate access.

When conducting security research activities related to the products covered by this Policy, researchers should:

  • Act in good faith
  • Avoid any impact on the availability of products, services, or systems
  • Not access, alter, destroy, or disclose third-party data; if they gain access to sensitive information, personal data, or credentials, they must immediately stop testing and promptly report the finding
  • Report vulnerabilities responsibly, limiting the information provided to the minimum necessary to validate the identified vulnerability
  • Keep the vulnerability confidential until a fix has been released or coordinated disclosure is completed

5. Unauthorized Activities

The following activities are not authorized under this Policy:

  • Denial-of-Service (DoS) attacks
  • Distributed Denial-of-Service (DDoS) attacks
  • Testing intended to degrade or disrupt the availability of services
  • Social engineering (e.g., phishing, vishing, smishing)
  • Installation, propagation, or execution of malware
  • Modification, deletion, or destruction of data
  • Persistency establishment on systems or devices
  • Lateral movement to systems unrelated to the initial attack vector
  • Publishing the vulnerability before coordinating disclosure

6. Handling of External Vulnerability Reports

External vulnerability reports will be reviewed and processed in accordance with Altice Labs’ vulnerability management procedures and applicable responsibilities. Activities include:

  • Acknowledge receipt of the report
  • Request additional information from the researcher, when necessary
  • Validate and verify the reported vulnerability, including its reproducibility
  • Identify affected products, versions, components, and dependencies
  • Assess the vulnerability’s impact, severity, and associated risks to customers, users, and other stakeholders
  • Determine and prioritize appropriate mitigation, containment, and remediation measures
  • Coordinate the development, testing, and release of security updates
  • Coordinate the responsible disclosure of the vulnerability, including coordination with customers, vendors, partners, third-party component maintainers, Computer Emergency Response Teams (CERTs), Computer Security Incident Response Teams (CSIRTs), or other relevant entities, when applicable
  • Provide status updates and relevant outcome information to the researcher where appropriate

Where information provided in a vulnerability report indicates an ongoing security incident or active exploitation, Altice Labs may activate its Incident Response Process in parallel with the vulnerability handling activities defined in this Policy.