Usamos cookies, que son pequeños ficheros de texto, para mejorar su experiencia en nuestra website y mostrarle contenido personalizado. Puede permitirlas todas o seleccionarlas individualmente.

Vulnerability Disclosure Policy

Vulnerability Disclosure Policy

At Creative we are committed to building secure and resilient products and services. We welcome good faith reports of suspected vulnerabilities affecting Creative products, software, systems, or services, and we value those who help us identify and address security issues responsibly. Please review this policy carefully before conducting any research or submitting a report.

Scope

For purposes of this policy, "Creative products, software, systems, or services" includes:

  1. Creative-branded consumer audio hardware devices and the embedded firmware running on them, including firmware distributed through over-the-air (OTA) or other update mechanisms (each such device, together with its embedded firmware, a "Creative Device");
  2. wireless and radio interfaces (including Bluetooth and Wi-Fi);
  3. companion desktop and mobile applications; and
  4. the associated cloud or backend services that support the foregoing, including firmware/OTA update servers, user account and authentication systems, and application backend services.

Research conducted on a Creative Device that you have lawfully purchased and own is within scope. Testing of the companion applications and the associated cloud or backend services is within scope only to the extent conducted against accounts, data, or assets that you own or are expressly authorized to assess, or against public-facing assets that Creative has expressly identified as in scope. All research remains subject to the guidelines and prohibited activities set out below.

How to Submit a Report

When submitting a vulnerability report, please provide sufficient information to enable Creative to reproduce and assess the issue. Where available, your report should include:

  • a clear description of the suspected vulnerability;
  • the affected product, software, service, model, and version;
  • the technical details and conditions necessary to reproduce the issue;
  • the potential impact of the vulnerability; and
  • your contact information so that we may communicate with you regarding the report.

We ask that researchers make reasonable efforts to avoid harm during security testing. Please do not take any action that could impair the confidentiality, integrity, availability, or safety of Creative products, software, systems, or services, or associated data. In particular, do not disable, bypass, or interfere with any product safety feature (including volume-limiting or hearing-protection controls) in a manner that could create a risk of physical harm to any user. Avoid accessing or retaining data beyond what is necessary to demonstrate the vulnerability, and stop testing immediately if you encounter sensitive data or risk service disruption.

Confidentiality and Coordinated Disclosure

Please maintain the confidentiality of your findings, along with any related information you learn or infer through your research, until we have completed our investigation and, where appropriate, implemented any necessary measures, and/or until we've coordinated disclosure with you. This helps protect our users and ensures the responsible handling of security issues. We'd appreciate you keeping this in mind even where we decide not to remediate, and even where the same or a related vulnerability might affect other Creative products, software, systems, or services that share a common component (for example, a chipset, codec, wireless stack, or licensed firmware).

Creative’s Response

Upon receipt of a report submitted under this policy, Creative will endeavor to:

  • acknowledge receipt of the report;
  • review the submission and determine whether additional information is required;
  • investigate the reported issue using appropriate internal resources;
  • prioritize remediation based on the nature, severity, exploitability, and potential impact of the vulnerability; and
  • communicate with the reporting party as appropriate during the review process.

Creative will use reasonable efforts to review reports and address confirmed vulnerabilities in a timely manner, but response and remediation timelines may vary based on issue complexity, product lifecycle, and operational constraints.

Guidelines for Permitted Research

This policy applies only to good faith security research conducted in a manner consistent with its terms. To remain within scope, you must:

  • act lawfully and in good faith;
  • avoid privacy violations, service interruption, destruction of data, and degradation of user experience;
  • test only against products, services, accounts, or assets that you own or are expressly authorized to assess, unless Creative has expressly identified particular public-facing assets as in scope for testing; and
  • promptly report any vulnerability discovered without exploiting it beyond what is reasonably necessary to confirm its existence.
  • conduct any wireless or radio-frequency testing (including Bluetooth or Wi-Fi) only against your own devices and in a manner that does not interfere with other users, devices, or licensed spectrum; and where a suspected vulnerability originates in a third-party component (for example, a chipset, codec, or licensed firmware supplied by another vendor), notify Creative so that we may coordinate with the upstream vendor as appropriate.

Activities to Avoid

To keep your research in scope and protect our users, please avoid the following activities, which are not permitted under this policy:

  • accessing, downloading, modifying, or deleting data belonging to others without authorization;
  • conducting testing that intentionally or recklessly disrupts or degrades Creative products, software, systems, or services;
  • using invasive, excessive, or disruptive automated scanning or testing methods against Creative infrastructure;
  • exploiting a vulnerability for any purpose other than its minimal verification;
  • engaging in phishing, pretexting, social engineering, or other deceptive practices against Creative personnel, users, customers, or partners;
  • conducting physical attacks against Creative Devices that you do not own (physical examination, teardown, or firmware extraction of a Creative Device that you have lawfully purchased and own is permitted, provided it does not endanger any other person or device);
  • conducting wireless pairing, testing, commands injection against Creative Devices that you do not own;
  • publicly disclosing a vulnerability before Creative has had a reasonable opportunity to investigate and remediate it.

Out of Scope Reports

Certain categories of findings are outside the scope of this policy or may not be prioritized for response. These include, without limitation:

  • reports based solely on automated scanning output without a clear demonstration of an actual security risk;
  • missing security best practices or theoretical weaknesses without a demonstrable exploit path or meaningful impact;
  • reports concerning end-of-life, outdated, or unsupported products, firmware, or services no longer maintained by Creative;
  • version disclosure, banner disclosure, stack traces, path disclosure, or verbose error messages that do not lead to a demonstrated security consequence;
  • weak SSL/TLS configuration findings or other cryptographic observations that do not present a clear, exploitable risk in context;
  • findings that require unlikely user interaction, physical access, man-in-the-middle positioning, or prior compromise of another account, unless significant security impact is clearly demonstrated; and
  • denial-of-service or resource exhaustion findings obtained through active testing, whether or not actual service disruption occurred.

Creative reserves the right to determine, in its discretion, whether a submission falls within scope and the priority assigned to it.

Legal Statement and Safe Harbor

If you conduct security research in good faith and in compliance with this policy, Creative will not initiate legal action against you solely on that basis, though we cannot bind third parties or law enforcement authorities.

This Safe Harbor applies only to the extent permitted by applicable law and only to claims Creative may bring on its own behalf. It does not provide immunity from third-party claims or liability under applicable law. If a third party initiates legal action in connection with activities Creative determines were conducted in compliance with this policy, we may, in our discretion, indicate that we regard such activities as authorized, but we are not obligated to provide legal representation, indemnification, or other support.

No Reward Program

While we are grateful for the time and effort researchers invest, this is not a paid program. Unless Creative expressly states otherwise in writing, submission of a report does not entitle the reporting party to any payment, bounty, compensation, public recognition, or other benefit.

Changes to This Policy

Creative may update, revise, suspend, or withdraw this policy at any time. The version in effect at the time the relevant activity occurred will govern Creative’s assessment of compliance.

Contact Information

To report a vulnerability or ask questions about this policy, please contact Creative through the security reporting channel at security@ctl.creative.com.