Security

Cybernetics Vulnerability Reward Program (VRP) Rules

We have long enjoyed a close relationship with the security research community. To honor all the cutting-edge external contributions that help us keep our users safe, we maintain a Vulnerability Reward Program for Cybernetics APP running continuously since November 2023.

Services in scope

In principle, any Cybernetics application subsidiary web service that handles reasonably sensitive user data is intended to be in scope. This includes virtually all the content in the following domains:

  • *.cybernetics.fr

For further services and devices that are also in scope, see the rules for the following reward programs:

Qualifying vulnerabilities

Any design or implementation issue that substantially affects the confidentiality or integrity of user data is likely to be in scope for the program. Common examples include: Cross-site scripting, Cross-site request forgery, Mixed-content scripts, Authentication or authorization flaws, Server-side code execution bugs. Note: In addition, significant abuse-related methodologies are also in scope for this program, if the reported attack scenario displays a design or implementation issue in a Cybernetics product that could lead to significant harm. An example of an abuse-related methodology would be a technique by which an attacker is able to abuse our API by exploiting a vulnerabilities that go undetected by our security systems.

Non-qualifying vulnerabilities

Out of concern for the availability of our services to all users, please do not attempt to carry out DoS attacks, leverage black hat SEO techniques, spam people, or do other similarly questionable things. We also discourage the use of any vulnerability testing tools that automatically generate very significant volumes of traffic.

Reward amounts for security vulnerabilities

Rewards for qualifying bugs range from $100 to $2000. The following table outlines the usual rewards chosen for the most common classes of bugs. To read more about our approach to vulnerability rewards you can read our article here.

Category Examples Applications that permit taking over a Cybernetics Account [1] Other highly sensitive applications [2] Normal Cybernetics applications Non-integrated acquisitions and other sandboxed or lower priority applications [3]
Vulnerabilities giving direct access to app.cybernetics.fr servers
Remote code executionCommand injection, deserialization bugs, sandbox escapes$2000$2000$2000$100 - $500
Unrestricted file system or database accessUnsandboxed XXE, SQL injection$2000$2000$2000$100 - $2000
Logic flaw bugs leaking or bypassing significant security controlsDirect object reference, remote user impersonation$2000$1000$2000$250
Vulnerabilities giving access to client or authenticated session of the logged-in victim
Execute code on the clientWeb: Cross-site scripting Mobile / Hardware: Code execution$2000$2000$1200$100
Other valid security vulnerabilitiesWeb: CSRF, Clickjacking Mobile / Hardware: Information leak, privilege escalation$100 - $1800$100 - $1800$100 - $1800$100