skip to main page

Product Security

As Your Global Automation Partner, TURCK stands for reliability, security and shared responsibility. Our Product Security Incident Response Team (PSIRT) offers you a trusted and secure way to report security-related vulnerabilities in our products. Every report helps us to make our solutions even more resilient – so that you can rely on TURCK in every application, anywhere in the world.

The TURCK Product Security Incident Response Team (PSIRT)

No product is 100 percent immune to every conceivable vulnerability—what matters is how openly and quickly a manufacturer addresses it. That is exactly what the TURCK PSIRT stands for: Whether you’re an independent security researcher, a customer in live operation, or a partner in a joint project who encounters a potential vulnerability—your report helps us make TURCK products continuously more secure. We review every report in a structured manner, keep you updated on the status of the investigation, and coordinate disclosure so that operators have sufficient time to implement countermeasures before details are made public. Find out here how to report a vulnerability to us and what information is helpful in doing so.

Report Potential Security Vulnerabilities

To report a potential security vulnerability in a TURCK product, please send us an email to the TURCK Product Security Incident Response Team (PSIRT) at psirt@turck.com
Reports can be submitted in German or English.

Information on encrypted communication:

  • PGP Public Key: Download here
  • Fingerprint: FC172F921F440FF1027C2564B3A9AC53F92C2EEC
  • When contacting us for the first time, please include your public key so that we can communicate using end-to-end encryption.

Please provide us with the following information:

In addition to the device type, any other details—if available—will help us classify your report quickly and accurately: The more complete the information, the faster we can assess the vulnerability and develop an appropriate countermeasure—and the sooner you’ll benefit from a solution that ensures the secure operation of your system.

  • Affected Devices (Model + Part Number)
  • Serial number or unique ID
  • Firmware/Software Version
  • Type of security vulnerability (e.g., “denial-of-service”)
  • Information on how the vulnerability can be exploited
  • Known Effects of the Security Vulnerability
  • Information on the public awareness of the security vulnerability (e.g., whether it has already been made public, or whether disclosure is planned or a timeline has been established)
  • Optional: Name, organization, and contact information

Please coordinate the disclosure of information about the security vulnerability with us so that we can provide operators of the affected products with mitigating or corrective measures (e.g., an update) in a timely manner.

If you have any questions about resolved or existing security vulnerabilities, please feel free to contact the PSIRT at psirt@turck.com.

Information on Security Vulnerabilities

TURCK is a partner of CERT@VDE, whose established infrastructure we use for the coordinated publication of security advisories—this provides you with structured, machine-readable information (CSAF) as well as an easy way to subscribe to feeds for ongoing updates.

TURCK publishes security advisories via CERT@VDE:

vdecert4-3