Product Security
AEM, and our family of brands, is committed to the security of the products we manufacture. This page explains how to report a suspected vulnerability, tampering, or cyberattack affecting an AEM product, consistent with our obligations under the EU Cyber Resilience Act (Regulation (EU) 2024/2847).
Report a vulnerability or security incident
If you have information about a potential vulnerability, tampering attempt, or cyberattack involving an AEM product, please notify our Product Security Team at:
We will acknowledge receipt of your report. Because the nature and severity of each report varies, we cannot guarantee a fixed response time, but reports involving actively exploited vulnerabilities or active incidents are prioritized.
What to include in your report
To help us assess and respond quickly, please include as much of the following as you can:
- The product name, model, and manufacturer (AEM or the specific AEM brand)
- Firmware or software version affected
- A clear description of the vulnerability or issue and how it can be reproduced
- The date, time, and environment in which it was observed
- Any supporting evidence (logs, screenshots, test steps, proof-of-concept)
- Your assessment of the potential impact, if known
Please do not include or attempt to obtain the following
- Passwords, access credentials, private keys, or other secrets
- Personal data or confidential information belonging to third parties
Please do not
- Attempt denial-of-service testing against production systems
- Use social engineering, phishing, or physical attacks against AEM personnel, customers, or facilities
- Access, modify, or delete data that is not your own
Scope
This process covers products for which AEM (or one of its business units, such as LAMBRECHT meteo GmbH) is the manufacturer, including their digital components and any third-party/supplier components incorporated into those products.
Our process
- Intake — your report is received and logged by our Product Security Team.
- Assessment — we validate and assess the severity and impact of the reported issue.
- Coordination and remediation — where required, we coordinate with affected business units, suppliers, and, in line with our obligations under the EU Cyber Resilience Act, the relevant national CSIRT and ENISA.
Responsible/coordinated disclosure
We ask that you give us a reasonable opportunity to investigate and address a reported vulnerability before disclosing it publicly, and that you act in good faith to avoid privacy violations, service disruption, and destruction of data during your research. We do not currently offer a bug bounty program, and we cannot guarantee compensation or public recognition for reports submitted through this channel.
Data protection
Any personal data you provide as part of a report (for example, your name or email address) will be used solely to process and respond to your report, in accordance with our Privacy Policy.
Manufacturer information
Advanced Environmental Monitoring (AEM)
12410 Milestone Center Drive, Suite 300
Germantown, MD 20876
USA Phone: 800-758-7246
For non-security matters, please visit Support or Contact Us.