Homepage > Services & Support > Cybersecurity Bulletin > Vulnerability Management Program

Hithium is committed to establishing a robust product cybersecurity vulnerability response system in accordance with international standards such as IEC 62443.This systematic process provides our customers with reliable assurance and works to minimize cybersecurity risks effectively.To efficiently address product cybersecurity vulnerabilities, Hithium has established a dedicated Product Security Incident Response Team (PSIRT). This team is responsible for responding to product security incidents and managing both known and potential vulnerabilities. Through transparent vulnerability disclosure procedures, the PSIRT promotes efficient and trusted industrial cybersecurity practices.

Hithium's Product Cybersecurity Vulnerability Management Program


Hithium's vulnerability management program is aligned with the IEC 62443-4-1 standard and follows the process outlined below:


1758705763409326Pb6N.png


n Receive and Acknowledge Cybersecurity Information: Upon receiving externally submitted cybersecurity information, the PSIRT will contact the submitter within two business days to confirm the issue. 

n Incident Assessment and Impact Analysis: The PSIRT will categorize the submitted cybersecurity information, assess the incident, and conduct an impact analysis to preliminarily determine whether emergency response should be initiated.

n Vulnerability Analysis and Research: The PSIRT will work with the product development team to evaluate the root cause and likelihood of the vulnerability, assess its severity, define its risk level, and explore solutions to mitigate risks or remediate the vulnerability. During this stage, the PSIRT will maintain active communication with the reporter.

n Vulnerability Handling: The PSIRT will collaborate with the product development team to develop software/firmware patches or determine appropriate risk mitigation measures. At the same time, the PSIRT will continue to monitor related information to ensure accurate evaluation of the vulnerability’s severity. If the vulnerability is high-risk and patch development requires significant time, emergency mitigation measures will be provided to customers prior to the completion of the final remediation.

n Vulnerability Disclosure: Once the vulnerability has been remediated, the PSIRT will publish the resolution results on Hithium’s official website under the “Cybersecurity Notice” section. The notice will include: a description of the vulnerability, potentially affected products and versions, mitigation measures, and the remediation plan.

 

The Hithium PSIRT team, in collaboration with the R&D team, analyzes and assesses vulnerabilities based on the Common Vulnerability Scoring System (CVSS) and other criteria defined in our Cybersecurity Vulnerability Management Program, such as likelihood and impact. Based on this assessment, a risk score is assigned, and a remediation timeframe is established according to the vulnerability's risk level. Throughout the remediation process, the PSIRT maintains communication with the vulnerability reporter as needed to support analysis, discuss solutions, and gather feedback.

 

For the latest information on product cybersecurity, please visit the“Cybersecurity Notice”page. Given the specific characteristics and critical safety requirements of energy storage products, software/firmware updates must not be performed by users independently. To obtain and install vulnerability patches and updates, please contact our After-Sales Service Engineers for assistance.

 

Reporting Product Cybersecurity Vulnerability 

 

If you have discovered a potential cybersecurity vulnerability in a Hithium product, please report it to us immediately via encrypted email at the address below. 

Providing the following information will help us facilitate a prompt and effective response.

1.Product model and software/firmware version

2.Vulnerability reproduction environment and steps (with logs or screenshots)

3.Proof-of-concept code (if applicable)

4.Description of the vulnerability exploitation scenario

5.Network packet capture data (e.g., Wireshark records)

6.Other relevant technical details

 

Hithium Cybersecurity Contact Email:IACS-CyberSecurity@Hithium.com


Disclaimer

Hithium reserves the right to modify this vulnerability management policy at any time. The most current version will always be made available on our official website (http://www.hithium.com). Hithium does not guarantee a response to every vulnerability report.By utilizing this document or any related links, you acknowledge that you shall assume all associated risks.



OK
Subscription Success
Congratulations on your successful subscription to HTHlUM news
Got it
Please leave your business requirements and our experts will contact you as soon as possible.
Pre-sale
After-sale
Media
Request Brochure
Get Quote
Full Name *
Email *
Phone *
You Are Interested In *
Cell
Module
Utility & Commercial System
Residential System
Region *
Afghanistan
Aland Islands
Albania
Algeria
American Samoa
Andorra
Angola
Anguilla
Antarctica
Antigua and Barbuda
Argentina
Armenia
Aruba
Australia
Austria
Azerbaijan
Bahamas
Bahrain
Bangladesh
Barbados
Belarus
Belgium
Belize
Benin
Bermuda
Bhutan
Bolivia
Bonaire, Sint Eustatius and Saba
Bosnia and Herzegovina
Botswana
Bouvet Island
Brazil
British Indian Ocean Territory
British Virgin Islands
Brunei Darussalam
Bulgaria
Burkina Faso
Burundi
Cabo Verde
Cambodia
Cameroon
Canada
Cayman Islands
Central African Republic
Chad
Chile
China
Christmas Island
Cocos (Keeling) Islands
Colombia
Comoros
Cook Islands
Costa Rica
Cote d'Ivoire
Croatia
Cuba
Curacao
Cyprus
Czech Republic
Democratic Republic of the Congo
Denmark
Djibouti
Dominica
Dominican Republic
Ecuador
Egypt
El Salvador
Equatorial Guinea
Eritrea
Estonia
Ethiopia
European Union
Falkland Islands
Faroe Islands
Federated States of Micronesia
Fiji
Finland
France
French Guiana
French Polynesia
French Southern Departments
Gabon
Gambia
Georgia
Germany
Ghana
Gibraltar
Greece
Greenland
Grenada
Guadeloupe
Guam
Guatemala
Guernsey
Guinea
Guinea-Bissau
Guyana
Haiti
Heard and McDonald Islands
Honduras
Hungary
Iceland
India
Indonesia
Iran
Iraq
Ireland
Isle of Man
Israel
Italy
Jamaica
Japan
Jersey
Jordan
Kazakhstan
Kenya
Kingdom of Eswatini
Kiribati
Kuwait
Kyrgyzstan
Laos
Latvia
Lebanon
Lesotho
Liberia
Libya
Liechtenstein
Lithuania
Luxembourg
Madagascar
Malawi
Malaysia
Maldives
Mali
Malta
Marshall Islands
Martinique
Mauritania
Mauritius
Mayotte
Mexico
Moldova
Monaco
Mongolia
Montenegro
Montserrat
Morocco
Mozambique
Myanmar
Namibia
NATO
Nauru
Nepal
Netherlands
New Caledonia
New Zealand
Nicaragua
Niger
Nigeria
Niue
Norfolk Island
North Korea
North Macedonia
Northern Mariana Islands
Norway
Oman
Orange
Pakistan
Palau
Panama
Papua New Guinea
Paraguay
Peru
Philippines
Pitcairn Islands Group
Poland
Portugal
Puerto Rico
Qatar
Republic of the Congo
Reunion
Romania
Russian Federation
Rwanda
Saint Barthelemy
Saint Helena
Saint Kitts and Nevis
Saint Lucia
Saint Martin
Saint Pierre and Miquelon
Saint Vincent and the Grenadines
Samoa
San Marino
Sao Tome and Principe
Saudi Arabia
Senegal
Serbia
Seychelles
Sierra Leone
Singapore
Sint Maarten (Dutch part)
Slovakia
Slovenia
Solomon Islands
Somalia
South Africa
South Georgia and the South Sandwich Islands
South Korea
South Sudan
Spain
Spitzbergen
Sri Lanka
State of Palestine
Sudan
Suriname
Sweden
Switzerland
Syria
Tajikistan
Tanzania
Thailand
Timor-Leste
Togo
Tokelau
Tonga
Trinidad and Tobago
Tunisia
Turkey
Turkmenistan
Turks and Caicos Islands
Tuvalu
Uganda
Ukraine
United Arab Emirates
United Kingdom
United Nations
United States Minor Outlying Islands
Uruguay
USA
Uzbekistan
Vanuatu
Vatican City
Venezuela
Vietnam
Virgin Islands of the United States
Wallis and Futuna Islands
Western Sahara
Yemen
Zambia
Zimbabwe
City *
Company *
Demand scale estimation *
MWh
GWh
Expected delivery time *
Other special requeirements
Preffered Method of contact *
By Email
By Phone
Captcha *
I agree that HiTHIUM may send me regular newsletters and up to date information on HiTHIUM products and services, promotions and news via e-mail, post and/or telephone in accordance with the data protection declaration, l can withdraw my consent at any time.
Pre-sale
After-sale
Media
Full Name
Email *
Phone *
Company *
Project Address *
City
State/Province
Zip Code
Country *
Urgent Level *
Very Urgent
Urgent
Nomal
Product Model *
Cell
Module
System
General Inquiry
Under Warrany *
Yes
No
Date of Purchase
Date of Installation
When This Issue Occur *
How Can We Help You With *
Consultation
Complaints
Repair
Training and Guidance
Installation and Commissioning
Regular Inspections
Contractual Services
Details of the Issue *
Reference Image
Captcha *
I agree that HiTHIUM may send me regular newsletters and up to date information on HiTHIUM products and services, promotions and news via e-mail, post and/or telephone in accordance with the data protection declaration, l can withdraw my consent at any time.
You can also get in touch with our service team by sending email with your pre-filled request form.
check email address here
Pre-sale
After-sale
Media
Media Name *
Media Address *
Full Name *
Position *
Email *
Phone *
Purpose of the letter *
Interview
Activity
Visit
Advertising
Other
Detailed requirement description *
Captcha *
I agree that HiTHIUM may send me regular newsletters and up to date information on HiTHIUM products and services, promotions and news via e-mail, post and/or telephone in accordance with the data protection declaration, l can withdraw my consent at any time.