How to submit your vulnerability and what to expect

There are two ways of submitting to the GSMA Coordinated Vulnerability Disclosure programme. You can download the submission form in Microsoft Word or Text version format and send it back to the GSMA, or you can fill the online form below

We request reporters of vulnerabilities to describe the vulnerability on the submission form, including:

This is usually sufficient information to enable the GSMA to consider the vulnerability and will allow for verification and identification of possible remediations. A Proof-of-Concept (POC) or more detailed description may be requested in the case of complex vulnerabilities.

The GSMA may ask a Reporter for more information throughout the consideration process.

Researcher Testimonial: Find out what the importance is of submitting a vulnerability to the CVD programme, the experience of working with the GSMA and the additional benefits of engagement with the mobile industry.

Submission Forms

Submission Form – Word Version
Submission Form – Text Version

Once you have completed this template, you should submit it by email to the GSMA on security@gsma.com.

The GSMA recommends that all vulnerability disclosure submissions are encrypted, but use of encryption is at the discretion of the finder.

Click here to view the CVD submission process.

Scope

Is the GSMA’s CVD programme the correct scheme to bring my research to?

The scope of the GSMA CVD Programme is security vulnerabilities that impact the mobile industry, primarily open standards based technologies.

The following items are out of scope for the CVD Programme.

For vulnerabilities affecting one manufacturer or network, please contact them directly – some vulnerability disclosure programmes from GSMA members can be found here.

For reporting vulnerabilities in GSMA websites or services please see here.

Research Expectations

The GSMA is grateful to Reporters who afford us the opportunity to consider their findings, liaise with the industry and define remediation and mitigation actions. However, participation in the CVD Programme requires that Reporters do not engage in activities that violate any local legislation or regulations and third party rights.

Reporters are asked to:

If there is any doubt, please contact security@gsma.com.

PGP details

PGP Details:

—–BEGIN PGP PUBLIC KEY BLOCK—–
Comment: User ID: R Brown 23 NEW
Comment: Valid from: 27/07/2023 14:10
Comment: Valid until: 05/08/2029 23:58
Comment: Type: 255-bit EdDSA (secret key available)
Comment: Usage: Signing, Encryption, Certifying User IDs
Comment: Fingerprint: 22150430A5020646BEF798B426B19DAC4B3DE074

mDMEZMJsshYJKwYBBAHaRw8BAQdABaTG0DOU2wffeJCaZpZ36VpCD5yx9v5DObSD
fJx/U7O0IFIgQnJvd24gMjMgTkVXIDxyYnJvd25AZ3NtYS5jb20+iJkEExYKAEEC
GwMFCwkIBwICIgIGFQoJCAsCBBYCAwECHgcCF4AWIQQiFQQwpQIGRr73mLQmsZ2s
Sz3gdAUCanMzpwUJC1Y/gQAKCRAmsZ2sSz3gdP/bAP9N8hlglCh984G6yF1qlxhw
8nC+l3HGgOsyrR7r6oOikAEA65si9o/fGawiwYToRMavbUXjDxJrdMnENhR7tBPC
aQG4OARkwmyyEgorBgEEAZdVAQUBAQdAQWoeEk/CMdWa1Cvf0eD74hqC+Pe/4ANR
XX2gDmvQ+TQDAQgHiH4EGBYKACYCGwwWIQQiFQQwpQIGRr73mLQmsZ2sSz3gdAUC
anMztgUJC1Y/kAAKCRAmsZ2sSz3gdD24AP9/9TNZxw4oancSzU7tHz/uhdQmcYai
pm5GyH6LmlwFRgEA5a0y8Kdlt4y5owKCVWoaRKjnRuP9MmXfZd+xwc+uPAw=
=9q50
—–END PGP PUBLIC KEY BLOCK—–

Submit your vulnerability

Online form

To submit documents or other attachments in addition to the information in this form, please email these to security@gsma.com.












Details such as:
* Preconditions/Assumptions for the attack.
* Traffic flows (if applicable).
* Effect and impact.
* Relevant specification clause numbers (if applicable).