1. Introduction
SMEG’s product approach is to combine high technological standards with attractive design to provide innovative and reliable appliances.
Guaranteeing the absolute reliability of our products is one of SMEG's main commitments, as evidenced by constant and rigorous control tests throughout the production process.
As a manufacturer of high quality and durable products, SMEG is therefore concerned about the security of users’ information and welcomes the contribution of external security researchers to improving the security of our connectable products and their related services.
This policy explains how security vulnerabilities and security incidents can be reported to SMEG and how SMEG manages such reports in a responsible and coordinated manner.
SMEG reserves the right to modify and update its Coordinated Vulnerability Disclosure Policy, as necessary to further ensure transparency and clarity in our dealings with external security researchers. SMEG Coordinated Vulnerability Disclosure Policy will therefore be applicable in its latest version.
We recommend reading this policy fully before you report a vulnerability and always acting in compliance with it.
We value those who take the time and effort to report security vulnerabilities according to this policy. However, we do not offer monetary rewards for vulnerability disclosures.
2. Scope
This policy applies to all connectable products, including their components, which are developed, manufactured and marketed by SMEG as well as to all their related services.
For a list of our products covered by this policy, please refer to the following page: SMEG's connectable appliances and services.
On each product page, you will find the related support period, which is the minimum length of time for which security updates will be provided. The possible expiration of the support period for a given product does not affect its operation: the product remains generally updateable, but we cannot guarantee updates for any security vulnerabilities found.
On the Security Advisories, we publish notices of vulnerabilities that have been discovered, either through SMEG's normal testing activities, or through security reports received via the dedicated online form, which are then verified and fixed by SMEG's laboratories.
3. Security Event Classification
For the purpose of this policy, SMEG distinguishes between the following categories:
- Vulnerability: a security weakness that could affect the confidentiality, integrity, availability or authenticity of a product, service or related data.
- Actively Exploited Vulnerability: a vulnerability for which there is evidence of malicious exploitation affecting a product with digital elements.
- Security Incident: an event affecting or potentially affecting the confidentiality, integrity, availability or authenticity of a product, related services or user data.
- Severe Security Incident: a security incident that has, or is capable of having, a significant impact on the security of a product, related services, user data or affected systems.
Reported security issues may be assessed and classified by SMEG as Vulnerabilities, Actively Exploited Vulnerabilities, Security Incidents or Severe Security Incidents, as appropriate and in accordance with applicable regulatory requirements and internal procedures.
Reports relating to any of the above categories may be submitted through the channels described in this policy.
4. How to Report a Security Vulnerabilty
If you believe you have identified a potential security issue affecting one of SMEG’s connectable products or related services, please share your findings by filling in the web form available at the following link: security report.
In order to speed up the reporting process, your message should include all the details of the security issue according to all the fields specified in the web form. More precisely, in your report please include details of:
-
Title: a concise summary facilitating the proper categorization of the submitted security issue;
-
Report Category: an indication of the issue's nature (security vulnerability, security incident), assisting SMEG in the assessment and mitigation activities;
-
Product Category: select the type of product or service the security issue relates to (e.g. oven, dishwasher, mobile application, etc.);
- Product Code: to identify the code of the product, see how-to-find-productcode-and-serialnumber;
- Product Serial Number: to identify the serial number of the product, see how-to-find-productcode-and-serialnumber;
-
Description: a brief description of the reported security issue and possible mitigations or recommendations;
-
Steps to Reproduce: provide clear and descriptive steps for replication, and test code if available;
-
Impact: the potential consequences of the reported security issue;
-
Severity: levels based on the reporter’s assessment of the potential security impact (low, medium, high, critical). Where applicable, CVSS scoring may be used as a reference;
-
Evidence of Active Exploitation: indicate whether the reported security issue is known or suspected to be actively exploited, and provide any supporting information if available;
-
Weakness: if you prefer, you can refer to the CWE (Common Weakness Enumerations) portal;
-
Supporting Files: e.g. screenshots or video;
-
Name, Surname and Contact E-mail.
The form also allows you to provide your first name, last name and email address. This information is not mandatory for submitting the security report but is required to notify you that your report has been taken into account, to send you updates on the report, and to request further details about the reported issue.
5. What to Expect
After confirming the submission of your security report, you will receive within two business days a confirmation message with a protocol number. This protocol number is the unique identifier which will be used to identify all subsequent SMEG updates relating to your security report.
Once a protocol number has been assigned to the security report, it will be recorded by our systems.
SMEG assesses reported security events considering their nature, severity, potential impact on users and services, and any evidence of active exploitation. The assessment and remediation of reported security issues may require varying amounts of time depending on their complexity, severity and potential impact.
Where contact details have been provided, SMEG will make reasonable efforts to provide status updates at key stages of the assessment, remediation and disclosure process. The frequency of updates may vary depending on the complexity and severity of the reported security issue.
If you have provided us with your contact details, we will aim to keep you informed of our progress on the submitted security report as soon as possible; otherwise, you are welcome to enquire about the status but should avoid doing so more than once every 14 days. This allows our teams to focus on the remediation.
If you have provided us with your contact details, we will notify you when the reported issue is remediated, and you may be invited to confirm that the solution covers the issue adequately.
SMEG Product Security Team will send all communications via the [email protected] address, which you can consider as the reference address for both general product cybersecurity information and for enquiries on the status of a submitted report.
To ensure consistent guidance and communication to affected users, SMEG encourages reporters to coordinate any public disclosure activities with SMEG.
Where appropriate, SMEG coordinates vulnerability handling, remediation and disclosure activities with reporters, suppliers, service providers and other relevant stakeholders in order to reduce potential risks for users, connected products and related services.
The final classification of reported vulnerabilities or security incidents, as well as the publication of any advisories or communications by SMEG, remains under the responsibility of SMEG.
6. Best Practices for Reporting Security Issues
In order to facilitate the handling of security reports, we provide below some of the best practices that we encourage you to follow when reporting security issues.
We invite you not to:
- Break any applicable law or regulations;
- Access unnecessary, excessive or significant amounts of data;
- Modify data in SMEG's systems or services;
- Use high-intensity invasive or destructive scanning tools to find vulnerabilities;
- Attempt or report any form of denial of service, e.g. overwhelming a service with a high volume of requests;
- Disrupt SMEG’s services or systems;
- Submit reports indicating that the services do not fully align with “best practice”, for example missing security headers;
- Disclose vulnerabilities or associated details through channels other than those described in this policy;
- Social engineer, ‘phish’ or physically attack the SMEG's staff or infrastructure;
- Demand financial compensation in order to disclose any vulnerabilities.
We invite you to:
-
Always comply with data protection rules and not violate the privacy of the SMEG’s users, staff, contractors, services or systems. You must not, for example, share, redistribute or fail to properly secure data retrieved from the systems or services;
-
Securely delete all data retrieved during your research as soon as it is no longer required or within 1 (one) month of the security issue being resolved, whichever occurs first (or as otherwise required by data protection law).
7. Legalities
This policy is designed to be compatible with common vulnerability disclosure good practice. It does not give you permission to act in any manner that is inconsistent with the law, or which might cause SMEG or partner organizations to be in breach of any legal obligations.
8. Regulatory Reporting
SMEG is committed to handling vulnerabilities and security incidents in accordance with applicable cybersecurity legislation and industry good practices.
Where required by applicable laws and regulations, SMEG notifies competent authorities, cooperates with relevant stakeholders, and communicates appropriate information, mitigation measures or corrective actions to affected users regarding Actively Exploited Vulnerabilities or Severe Security Incidents.
Such regulatory and communication activities are managed through SMEG’s internal security processes and do not require any additional action from the reporting party.
Version: 11 September 2026