Skip to footer
  • Create new account
  • Reset your password

User account menu

  • Log in
Home

Main navigation

  • Home
  • About DMTF
    • All About DMTF
    • Frequently Asked Questions
    • Members List
    • DMTF Officers
      • All DMTF Officers
      • DMTF Executive Biographies
    • DMTF Officer Hall of Fame
    • DMTF Fellows
    • DMTF Star Award Recipients
      • All Star Award Recipients
      • Super Star Award Recipients
    • Working Groups and Committees
    • Alliance Partners
    • Academic Alliances
    • ANSI/ISO Adoptions and Alliance Activities
    • Policies
    • Patent Disclosures
    • Copyright Statement
    • Contact Us
  • Standards & Technology
    • Standard and Technology Overview
    • Feedback and Technology Submission Portal
    • DMTF Security Disclosures
    • Security Issue Reporting
    • Adopters of DMTF Standards
      • Adopters of DMTF Standards List
      • Adopter Application Form
    • All DMTF Standard Publications
      • Published Documents
      • ANSI/ISO Adoptions and Alliance Activities
      • Open Source Projects Using DMTF Technologies
      • Historical Documents
      • International Translated DMTF Specifications
      • Management Profiles
      • Works in Progress
    • Cloud Auditing Data Federation
    • Common Diagnostic Model
    • Cloud Management Initiative
    • Common Information Model
    • Configuration Management Database Federation
    • Desktop and Mobile Architecture for System Hardware
    • Network Management Initiative
    • Open Virtualization Format
    • Platform Management Communications Infrastructure
    • Redfish®
    • Security Protocols and Data Models
    • Systems Management Architecture for Server Hardware
    • SMBIOS
    • Virtualization Management
    • Web-Based Enterprise Management
    • Web Services Management
  • News & Events
    • All News and Events
    • Events
      • Events
      • Past Events
        • 2023 APTS
    • DMTF Press Releases
    • In the News
    • DMTF Speaker Request Form
    • Press Kit
    • Newsletter Archive
  • Education
    • Presentations
    • White Papers
    • Webinars
    • Open Source
    • Newsletter
  • Conformance
    • DMTF Conformance Programs
    • DASH Conformance Program
    • DMTF Certification Registry
  • Join
    • Join the DMTF
    • Benefits
    • Membership Levels
    • Sign Up
      • Individual Access
      • New Company
    • Join the Forums

DMTF Security Issue Reporting Process

Breadcrumb

  • Home
  • DMTF Security Issue Reporting Process

The following is a summary of the Security Response Process within the DMTF. If you have any information regarding security issues or vulnerabilities in DMTF standards (https://www.dmtf.org/standards) or DMTF open source implementations (https://github.com/DMTF), please report it to us immediately. DMTF's Security Response Task Force (SRTF) is chartered to coordinate the management and response for all reported security vulnerabilities in DMTF published artifacts.

Reporting a Security Issue

Please report the security issue or vulnerability via the DMTF Feedback Portal.

In order to help identify the issue in a timely manner, please include the following required information in document form (txt, rtf, docx preferred) as an attachment to the submission:

  •   Finder's email
  •   Vulnerability description with technical details, including how to reproduce the exploitation and the consequence of the exploitation.
  •   Impacted standard and its version
  •   Impacted reference code and its branch version
  •   Impacted production and production version

Once DMTF receives the report, SRTF administrator will acknowledge your email and may contact you for further information via secured email. All correspondence will take place with PGP email encryption.

Handling Security Issues

Once the security issue has submitted via the Feedback Portal and SRTF administration has confirmed its receipt, the vulnerability handling activities will proceed in the following phases:

  • Triage - determine the scope, severity, impact etc.
  • Mitigation - create the fix.
  • Embargo - let production apply the fix before publishing.
  • Disclosure - publish the mitigation.


DMTF SRTF will coordinate with security experts and domain area experts to review the issue, then provide and publish mitigation as soon as possible.
The timeline depends on many factors, including but not limited to:  issue complexity,  impact scope, involved components and production stage.

Usually, the embargo time for a software vulnerability is short, while the embargo time for a firmware or hardware vulnerability is longer because of the differences in the component update process.

Before the mitigation is disclosed publicly, the mitigation will be posted to the DMTF Security Announcement GitHub repository. If your corporation is using the DMTF standard or DMTF reference code in the production, you may register to get the mitigation information and adopt it before the disclosure. A corporate email address is required to join the Security Announcement repository.

Publication of Security Advisory

After embargo phase, DMTF will disclose mitigation through public security advisory, including below information:

  • Publication data
  • Vulnerability record - [CVE](https://cve.mitre.org/)
  • Severity scoring - [CVSS](https://www.first.org/cvss/)
  • Detail of the vulnerability
  • Mitigation - specification update and/or reference code patch
  • Acknowledgement

The advisory for DMTF standards will be included on the public pages of the authoring body.
The advisory for DMTF reference code will be included in each reference code github repository.

 

 

 

Standards & Technology

  • Standard and Technology Overview
  • Feedback and Technology Submission Portal
  • DMTF Security Disclosures
  • Security Issue Reporting
  • Adopters of DMTF Standards
  • All DMTF Standard Publications
  • Cloud Auditing Data Federation
  • Common Diagnostic Model
  • Cloud Management Initiative
  • Common Information Model
  • Configuration Management Database Federation
  • Desktop and Mobile Architecture for System Hardware
  • Network Management Initiative
  • Open Virtualization Format
  • Platform Management Communications Infrastructure
  • Redfish®
  • Security Protocols and Data Models
  • Systems Management Architecture for Server Hardware
  • SMBIOS
  • Virtualization Management
  • Web-Based Enterprise Management
  • Web Services Management

Policies | Site Map | Contact Us | Administrative Login

Copyright © 2025 DMTF. All rights reserved.