DESIGN TOOLS
Security

Report a product security issue

How to report a product security issue

To report a product security issue in any Micron product:
When emailing Micron PSIRT, please do so securely using the Micron PSIRT PGP Key

Micron Product Security Incident Response Team

Micron’s Product Security Incident Response Team (PSIRT) is responsible for the identification, assessment, and disposition of risks related to potential vulnerabilities involving Micron products. Our PSIRT processes and procedures follow guidelines and practices prescribed by the Forum of Incident Response and Security Teams (FIRST) and the International Organization for Standardization, to include ISO/IEC 29147:2018 and ISO/IEC 30111:2019.  

Micron PSIRT uses FIRST’s Common Vulnerability Scoring System version 4.0 (CVSS v4.0) to rate the severity of validated vulnerabilities involving Micron products.  The CVSS model enables a common scoring method and a common language to communicate the characteristics and impacts of exploited vulnerabilities. The scoring system consists of four metric groups (Base, Temporal, Environmental, and Supplemental) that establish a measurement of how much concern a vulnerability warrants by assigning a numerical value. 

Our process

Micron is steadfastly committed to assessing and remediating a discovered or reported security vulnerability to minimize the impact on our customers and product users. Our PSIRT process is based on the best practices published by FIRST.

Secure by design product development chart