{"id":3552,"date":"2022-01-07T17:52:38","date_gmt":"2022-01-07T17:52:38","guid":{"rendered":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/?page_id=3552"},"modified":"2026-08-17T14:18:35","modified_gmt":"2026-08-17T13:18:35","slug":"cvd-submit-a-vulnerability","status":"publish","type":"page","link":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/cvd-submit-a-vulnerability\/","title":{"rendered":"How to submit your vulnerability and what to expect"},"content":{"rendered":"<p><iframe loading=\"lazy\" title=\"GSMA Coordinated Vulnerability Disclosure (CVD) Programme\" width=\"900\" height=\"506\" src=\"https:\/\/www.youtube.com\/embed\/cDa4CIhg0g8?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe><\/p>\n\n\n\n<p>There are two ways of submitting to the GSMA Coordinated Vulnerability Disclosure programme. You can download the submission form in Microsoft Word or Text version format and send it back to the GSMA, or you can fill the <a href=\"#submit-form\">online form below<\/a>.&nbsp;<\/p>\n\n\n\n<p>We request reporters of vulnerabilities to describe the vulnerability on the submission form, including:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Identification of the vulnerable target(s)<\/li>\n\n\n\n<li>A description of the vulnerability<\/li>\n\n\n\n<li>Operations carried out to exploit the vulnerability<\/li>\n<\/ul>\n\n\n\n<p>This is usually sufficient information to enable the GSMA to consider the vulnerability and will allow for verification and identification of possible remediations. A Proof-of-Concept (POC) or more detailed description may be requested in the case of complex vulnerabilities.<\/p>\n\n\n\n<p>The GSMA may ask a Reporter for more information throughout the consideration process.<\/p>\n\n\n\n<p>Researcher Testimonial: Find out what the importance is of submitting a vulnerability to the CVD programme, the experience of working with the GSMA and the additional benefits of engagement with the mobile industry.<\/p>\n\n\n\n<div class=\"wp-block-gsma-video-pod banner_right-img_block gsma-load-hidden\">\n<div class=\"wp-block-group banner_right-img_container gsma-load-hidden\"><div class=\"wp-block-group__inner-container is-layout-flow wp-block-group-is-layout-flow\">\n<div class=\"wp-block-columns banner_right-img_columns is-layout-flex wp-container-core-columns-is-layout-1 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column banner_right-img_column_left is-layout-flow wp-block-column-is-layout-flow\">\n<h2 class=\"wp-block-heading banner_right-img_title\" id=\"h-what-do-experts-say-about-the-cvd-programme\">What do experts say about the CVD programme?<\/h2>\n\n\n\n<p class=\"banner_right-img_blurb\">David Ruprecht, Postdoctoral Researcher in 5G Security, explains the CVD experience and value of the programme<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column banner_right-img_column_right is-layout-flow wp-block-column-is-layout-flow\"><div id=\"video-wrap-1\" class=\"gsma-vid-wrap wrap-theo respond\" data-width=\"620\" data-height=\"345\" data-image=\"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-content\/uploads\/2022\/05\/Researcher-Video-interview-1.jpg\" data-mute=\"false\" data-controls=\"true\" data-start-level=\"3\" data-miid=\"480241850\" data-fid=\"0000116234130\"><div class=\"gsmavideo\" id=\"ys1\" data-link=\"https:\/\/platform.vixyvideo.com\/p\/557\/sp\/55700\/playManifest\/entryId\/0_z6oor71j\/format\/applehttp\/protocol\/https\/a.m3u8\" data-poster=\"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-content\/uploads\/2022\/05\/Researcher-Video-interview-1.jpg\" style=\"width:100%;height:auto;\" controls=\"controls\" loop=\"true\" data-poster=\"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-content\/uploads\/2022\/05\/Researcher-Video-interview-1.jpg\"><\/div><\/div>\n<\/div>\n<\/div>\n<\/div><\/div>\n<\/div>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-submission-forms\">Submission Forms<\/h2>\n\n\n\n<p><a href=\"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-content\/uploads\/2019\/03\/GSMA-Coordinated-Vulnerability-Disclosure-Word-Template-2025.docx\" target=\"_blank\" rel=\"noreferrer noopener\">Submission Form &#8211; Word Version<\/a><br><a href=\"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-content\/uploads\/2019\/07\/GSMA-Coordinated-Vulnerability-Disclosure-Text-Template.txt\" target=\"_blank\" rel=\"noreferrer noopener\">Submission Form &#8211; Text Version<\/a><\/p>\n\n\n\n<p>Once you have completed this template, you should submit it by email to the GSMA on&nbsp;<a href=\"mailto:security@gsma.com\">security@gsma.com<\/a>.<\/p>\n\n\n\n<p>The GSMA recommends that all vulnerability disclosure submissions are encrypted, but use of encryption is at the discretion of the finder.<\/p>\n\n\n\n<p><a href=\"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-content\/uploads\/2021\/12\/1135_GSMA-CVD-infographic-v3.pdf\">Click here<\/a> to view the CVD submission process. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Scope<\/h2>\n\n\n\n<p>Is the GSMA\u2019s CVD programme the correct scheme to bring my research to?<\/p>\n\n\n<p><iframe loading=\"lazy\" title=\"GSMA CVD Information for Researchers\" width=\"900\" height=\"506\" src=\"https:\/\/www.youtube.com\/embed\/2BAK0-OYqjY?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe><\/p>\n\n\n\n<p>The scope of the GSMA CVD Programme is security vulnerabilities that impact the mobile industry, primarily open standards based technologies.<\/p>\n\n\n\n<p>The following items are <strong>out of scope<\/strong> for the CVD Programme.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Research or information on a vulnerability which has previously been made public. Research or information on a vulnerability which is already in the public domain is out of scope for inclusion in the Acknowledgements page, but may be considered through the CVD Programme in order to develop remediations.<\/li>\n\n\n\n<li>Services or products provided by a single Manufacturer or Manufacturer group, these should be reported to the relevant Manufacturer.<\/li>\n\n\n\n<li>Services or products provided by a single company or group of companies. These should be reported to the relevant company.<\/li>\n\n\n\n<li>Submissions by GSMA Members, Associate Members and Rapporteurs where they are working on the topic as part of an Activity. These should be reported through the relevant Activity.<\/li>\n<\/ul>\n\n\n\n<p>For vulnerabilities affecting one manufacturer or network, please contact them directly \u2013 some vulnerability disclosure programmes from&nbsp;<a href=\"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/gsma-coordinated-vulnerability-disclosure-programme\/gsma-members-vulnerability-disclosure-programmes\/\">GSMA members can be found here<\/a>.<\/p>\n\n\n\n<p>For reporting vulnerabilities in GSMA websites or services please see&nbsp;<a href=\"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/coordinated-vulnerability-disclosure-programme-gsma-assets\/\">here<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Research Expectations<\/h2>\n\n\n\n<p>The GSMA is grateful to Reporters who afford us the opportunity to consider their findings, liaise with the industry and define remediation and mitigation actions. However, participation in the CVD Programme requires that Reporters do not engage in activities that violate any local legislation or regulations and third party rights.<\/p>\n\n\n\n<p>Reporters are asked to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Not abuse the reported vulnerability. For example, downloading more data than is necessary to demonstrate the vulnerability, or changing\/deleting live systems, settings or data.<\/li>\n\n\n\n<li>Exercise caution and restraint with regard to personal data and not intentionally engaging in attacks against third parties, social engineering, denial-of-service attacks, spamming or otherwise causing a nuisance to other users.<\/li>\n<\/ul>\n\n\n\n<p>If there is any doubt, please contact <a href=\"mailto:security@gsma.com\">security@gsma.com<\/a>.<\/p>\n\n\n<div class=\"shortcode_faq\"><div class=\"faq_question  gsmacolor_cyan\"><div class=\"faqicon\"><i class=\"fas fa-plus\"><\/i><\/div><div class=\"faqtext\">PGP details<\/div><\/div><div class=\"faq_answer  \"><\/p>\n<h4><a id=\"pgp\"><\/a>PGP Details:<\/h4>\n<p>&#8212;&#8211;BEGIN PGP PUBLIC KEY BLOCK&#8212;&#8211;<br \/>\nComment: User ID: R Brown 23 NEW <rbrown@gsma.com><br \/>\nComment: Valid from: 27\/07\/2023 14:10<br \/>\nComment: Valid until: 05\/08\/2029 23:58<br \/>\nComment: Type: 255-bit EdDSA (secret key available)<br \/>\nComment: Usage: Signing, Encryption, Certifying User IDs<br \/>\nComment: Fingerprint: 22150430A5020646BEF798B426B19DAC4B3DE074<\/p>\n<p>mDMEZMJsshYJKwYBBAHaRw8BAQdABaTG0DOU2wffeJCaZpZ36VpCD5yx9v5DObSD<br \/>\nfJx\/U7O0IFIgQnJvd24gMjMgTkVXIDxyYnJvd25AZ3NtYS5jb20+iJkEExYKAEEC<br \/>\nGwMFCwkIBwICIgIGFQoJCAsCBBYCAwECHgcCF4AWIQQiFQQwpQIGRr73mLQmsZ2s<br \/>\nSz3gdAUCanMzpwUJC1Y\/gQAKCRAmsZ2sSz3gdP\/bAP9N8hlglCh984G6yF1qlxhw<br \/>\n8nC+l3HGgOsyrR7r6oOikAEA65si9o\/fGawiwYToRMavbUXjDxJrdMnENhR7tBPC<br \/>\naQG4OARkwmyyEgorBgEEAZdVAQUBAQdAQWoeEk\/CMdWa1Cvf0eD74hqC+Pe\/4ANR<br \/>\nXX2gDmvQ+TQDAQgHiH4EGBYKACYCGwwWIQQiFQQwpQIGRr73mLQmsZ2sSz3gdAUC<br \/>\nanMztgUJC1Y\/kAAKCRAmsZ2sSz3gdD24AP9\/9TNZxw4oancSzU7tHz\/uhdQmcYai<br \/>\npm5GyH6LmlwFRgEA5a0y8Kdlt4y5owKCVWoaRKjnRuP9MmXfZd+xwc+uPAw=<br \/>\n=9q50<br \/>\n&#8212;&#8211;END PGP PUBLIC KEY BLOCK&#8212;&#8211;<\/p>\n<p>\n<\/div><\/div>\n\n\n\n<h2 id=\"submit-form\">Submit your vulnerability<\/h2>\n\n\n<div class=\"shortcode_faq\"><div class=\"faq_question  gsmacolor_blue\"><div class=\"faqicon\"><i class=\"fas fa-plus\"><\/i><\/div><div class=\"faqtext\">Online form<\/div><\/div><div class=\"faq_answer  \"><\/p>\n<p>To submit documents or other attachments in addition to the information in this form, please email these to <a href=\"mailto:security@gsma.com\">security@gsma.com<\/a>.<\/p>\n<p><style>.wForm form{text-align: left;}<\/style><!-- FORM: HEAD SECTION -->\n    <meta http-equiv=\"Content-Type\" content=\"text\/html; charset=utf-8\" \/>\n    <meta name=\"referrer\" content=\"no-referrer-when-downgrade\">\n    <!-- THIS SCRIPT NEEDS TO BE LOADED FIRST BEFORE wforms.js -->\n    <script type=\"text\/javascript\" data-for=\"FA__DOMContentLoadedEventDispatch\" src=\"https:\/\/gsma.tfaforms.net\/js\/FA__DOMContentLoadedEventDispatcher.js\" defer><\/script>\n                    <style>\n                    .captcha {\n                        padding-bottom: 1em !important;\n                    }\n                    .wForm .captcha .oneField {\n                        margin: 0;\n                        padding: 0;\n                    }\n                <\/style>\n                <script type=\"text\/javascript\">\n                    \/\/ initialize our variables\n                    var captchaReady = 0;\n                    var wFORMSReady = 0;\n                    var isConditionalSubmitEnabled = false;\n\n                    \/\/ when wForms is loaded call this\n                    var wformsReadyCallback = function () {\n                        \/\/ using this var to denote if wForms is loaded\n                        wFORMSReady = 1;\n                        isConditionalSubmitEnabled = document.getElementById('submit_button').hasAttribute('data-condition');\n                        \/\/ call our recaptcha function which is dependent on both\n                        \/\/ wForms and an async call to google\n                        \/\/ note the meat of this function wont fire until both\n                        \/\/ wFORMSReady = 1 and captchaReady = 1\n                        onloadCallback();\n                    }\n                    var gCaptchaReadyCallback = function() {\n                        \/\/ using this var to denote if captcha is loaded\n                        captchaReady = 1;\n                        isConditionalSubmitEnabled = document.getElementById('submit_button').hasAttribute('data-condition');\n                        \/\/ call our recaptcha function which is dependent on both\n                        \/\/ wForms and an async call to google\n                        \/\/ note the meat of this function wont fire until both\n                        \/\/ wFORMSReady = 1 and captchaReady = 1\n                        onloadCallback();\n                    };\n\n                    \/\/ add event listener to fire when wForms is fully loaded\n                    document.addEventListener(\"wFORMSLoaded\", wformsReadyCallback);\n\n                    var enableSubmitButton = function() {\n                        var submitButton = document.getElementById('submit_button');\n                        var explanation = document.getElementById('disabled-explanation');\n                        var isConditionalSubmitConditionMet = wFORMS.behaviors.condition.isConditionalSubmitConditionMet;\n                        if (\n                            submitButton != null &&\n                            (isConditionalSubmitEnabled && isConditionalSubmitConditionMet) ||\n                            !isConditionalSubmitEnabled\n                        )\n                        {\n                            submitButton.removeAttribute('disabled');\n                            if (explanation != null) {\n                                explanation.style.display = 'none';\n                            }\n                        }\n                    };\n                    var disableSubmitButton = function() {\n                        var submitButton = document.getElementById('submit_button');\n                        var explanation = document.getElementById('disabled-explanation');\n                        if (submitButton != null) {\n                            submitButton.disabled = true;\n                            if (explanation != null) {\n                                explanation.style.display = 'block';\n                            }\n                        }\n                    };\n\n                    \/\/ call this on both captcha async complete and wforms fully\n                    \/\/ initialized since we can't be sure which will complete first\n                    \/\/ and we need both done for this to function just check that they are\n                    \/\/ done to fire the functionality\n                    var onloadCallback = function () {\n                        \/\/ if our captcha is ready (async call completed)\n                        \/\/ and wFORMS is completely loaded then we are ready to add\n                        \/\/ the captcha to the page\n                        if (captchaReady && wFORMSReady) {\n                            \/\/ Prevent both concurrent and sequential executions\n                            if (window.isCreatingCaptcha || window.hasCaptchaRendered) {\n                                return;\n                            }\n                            window.isCreatingCaptcha = true;\n\n                            try {\n                                var submitButton = document.getElementById('submit_button');\n                                var formContainer = submitButton.closest('form') || submitButton.closest('.wFormContainer');\n                                var faCaptcha = null;\n\n                                if (formContainer) {\n                                    faCaptcha = formContainer.querySelector('#google-captcha');\n                                }\n\n                                \/\/ Also check if captcha was appended to body as fallback (look for FA-specific structure)\n                                if (!faCaptcha) {\n                                    var bodyCaptchas = document.querySelectorAll('body > #google-captcha');\n                                    for (var i = 0; i < bodyCaptchas.length; i++) {\n                                        \/\/ Verify it's a FormAssembly captcha by checking for specific structure\n                                        if (bodyCaptchas[i].querySelector('.captcha .oneField .g-recaptcha')) {\n                                            faCaptcha = bodyCaptchas[i];\n                                            break;\n                                        }\n                                    }\n                                }\n\n                                if (faCaptcha) { \n                                    if (faCaptcha.parentNode) {\n                                        faCaptcha.parentNode.removeChild(faCaptcha);\n                                    } \n                                }\n\n                            \/\/ Now create a new captcha container\n                            var captchaContainer = document.createElement('div');\n                            captchaContainer.id = 'google-captcha';\n                            \n                            var captchaDiv = document.createElement('div');\n                            captchaDiv.className = 'captcha';\n                            \n                            var oneFieldDiv = document.createElement('div');\n                            oneFieldDiv.className = 'oneField';\n                            \n                            var recaptchaElement = document.createElement('div');\n                            recaptchaElement.id = 'g-recaptcha-render-div';\n                            recaptchaElement.className = 'g-recaptcha';\n                            \n                            var errorDiv = document.createElement('div');\n                            errorDiv.className = 'g-captcha-error';\n                            \n                            var helpDiv = document.createElement('div');\n                            helpDiv.className = 'captchaHelp';\n                            helpDiv.innerHTML = 'reCAPTCHA helps prevent automated form spam.<br>';\n                            \n                            var disabledDiv = document.createElement('div');\n                            disabledDiv.id = 'disabled-explanation';\n                            disabledDiv.className = 'captchaHelp';\n                            disabledDiv.style.display = 'block';\n                            disabledDiv.innerHTML = 'The submit button will be disabled until you complete the CAPTCHA.';\n                            \n                            oneFieldDiv.appendChild(recaptchaElement);\n                            oneFieldDiv.appendChild(errorDiv);\n                            oneFieldDiv.appendChild(document.createElement('br'));\n                            captchaDiv.appendChild(oneFieldDiv);\n                            captchaDiv.appendChild(helpDiv);\n                            captchaDiv.appendChild(disabledDiv);\n                            captchaContainer.appendChild(document.createElement('br'));\n                            captchaContainer.appendChild(captchaDiv);\n                            \n                            if (submitButton && submitButton.parentNode) {\n                                submitButton.parentNode.insertBefore(captchaContainer, submitButton);\n                            } else {\n                                \/\/ Fallback: append to body if submit button not found.\n                                document.body.appendChild(captchaContainer);\n                            }\n                        } finally {\n                            window.isCreatingCaptcha = false;\n                        }\n                            \n                            grecaptcha.enterprise.render('g-recaptcha-render-div', {\n                                'sitekey': '6LfMg_EaAAAAAMhDNLMlgqDChzmtYHlx1yU2y7GI',\n                                'theme': 'light',\n                                'size': 'normal',\n                                'callback': 'enableSubmitButton',\n                                'expired-callback': 'disableSubmitButton'\n                            });\n                            window.hasCaptchaRendered = true;\n                            var oldRecaptchaCheck = parseInt('1');\n                            if (oldRecaptchaCheck === -1) {\n                                var standardCaptcha = document.getElementById(\"tfa_captcha_text\");\n                                standardCaptcha = standardCaptcha.parentNode.parentNode.parentNode;\n                                standardCaptcha.parentNode.removeChild(standardCaptcha);\n                            }\n\n                            if (!wFORMS.instances['paging']) {\n                                document.getElementById(\"g-recaptcha-render-div\").parentNode.parentNode.parentNode.style.display = \"block\";\n                                \/\/document.getElementById(\"g-recaptcha-render-div\").parentNode.parentNode.parentNode.removeAttribute(\"hidden\");\n                            }\n                            document.getElementById(\"g-recaptcha-render-div\").getAttributeNode('id').value = 'tfa_captcha_text';\n\n                            var captchaError = '';\n                            if (captchaError == '1') {\n                                var errMsgText = 'The CAPTCHA was not completed successfully.';\n                                var errMsgDiv = document.createElement('div');\n                                errMsgDiv.id = \"tfa_captcha_text-E\";\n                                errMsgDiv.className = \"err errMsg\";\n                                errMsgDiv.innerText = errMsgText;\n                                var loc = document.querySelector('.g-captcha-error');\n                                loc.insertBefore(errMsgDiv, loc.childNodes[0]);\n\n                                \/* See wFORMS.behaviors.paging.applyTo for origin of this code *\/\n                                if (wFORMS.instances['paging']) {\n                                    var b = wFORMS.instances['paging'][0];\n                                    var pp = base2.DOM.Element.querySelector(document, wFORMS.behaviors.paging.CAPTCHA_ERROR);\n                                    if (pp) {\n                                        var lastPage = 1;\n                                        for (var i = 1; i < 100; i++) {\n                                            if (b.behavior.isLastPageIndex(i)) {\n                                                lastPage = i;\n                                                break;\n                                            }\n                                        }\n                                        b.jumpTo(lastPage);\n                                    }\n                                }\n                            }\n                        }\n                    }\n                <\/script>\n                                    <script src='https:\/\/www.google.com\/recaptcha\/enterprise.js?onload=gCaptchaReadyCallback&render=explicit&hl=en_US' async\n                        defer><\/script>\n                <script type=\"text\/javascript\">\n                    document.addEventListener(\"DOMContentLoaded\", function() {\n                        var warning = document.getElementById(\"javascript-warning\");\n                        if (warning != null) {\n                            warning.parentNode.removeChild(warning);\n                        }\n                        var oldRecaptchaCheck = parseInt('1');\n                        if (oldRecaptchaCheck !== -1) {\n                            var explanation = document.getElementById('disabled-explanation');\n                            var submitButton = document.getElementById('submit_button');\n                            if (submitButton != null) {\n                                submitButton.disabled = true;\n                                if (explanation != null) {\n                                    explanation.style.display = 'block';\n                                }\n                            }\n                        }\n                    });\n                <\/script>\n                <script type=\"text\/javascript\">\n        document.addEventListener(\"FA__DOMContentLoaded\", function(){\n            const FORM_TIME_START = Math.floor((new Date).getTime()\/1000);\n            let formElement = document.getElementById(\"tfa_0\");\n            if (null === formElement) {\n                formElement = document.getElementById(\"0\");\n            }\n            let appendJsTimerElement = function(){\n                let formTimeDiff = Math.floor((new Date).getTime()\/1000) - FORM_TIME_START;\n                let cumulatedTimeElement = document.getElementById(\"tfa_dbCumulatedTime\");\n                if (null !== cumulatedTimeElement) {\n                    let cumulatedTime = parseInt(cumulatedTimeElement.value);\n                    if (null !== cumulatedTime && cumulatedTime > 0) {\n                        formTimeDiff += cumulatedTime;\n                    }\n                }\n                let jsTimeInput = document.createElement(\"input\");\n                jsTimeInput.setAttribute(\"type\", \"hidden\");\n                jsTimeInput.setAttribute(\"value\", formTimeDiff.toString());\n                jsTimeInput.setAttribute(\"name\", \"tfa_dbElapsedJsTime\");\n                jsTimeInput.setAttribute(\"id\", \"tfa_dbElapsedJsTime\");\n                jsTimeInput.setAttribute(\"autocomplete\", \"off\");\n                if (null !== formElement) {\n                    formElement.appendChild(jsTimeInput);\n                }\n            };\n            if (null !== formElement) {\n                if(formElement.addEventListener){\n                    formElement.addEventListener('submit', appendJsTimerElement, false);\n                } else if(formElement.attachEvent){\n                    formElement.attachEvent('onsubmit', appendJsTimerElement);\n                }\n            }\n        });\n    <\/script>\n\n    <link href=\"https:\/\/gsma.tfaforms.net\/dist\/form-builder\/5.0.0\/wforms-layout.css?v=1788154697\" rel=\"stylesheet\" type=\"text\/css\" \/>\n\n    <link href=\"https:\/\/gsma.tfaforms.net\/uploads\/themes\/theme-34.css\" rel=\"stylesheet\" type=\"text\/css\" \/>\n    <link href=\"https:\/\/gsma.tfaforms.net\/dist\/form-builder\/5.0.0\/wforms-jsonly.css?v=1788154697\" rel=\"alternate stylesheet\" title=\"This stylesheet activated by javascript\" type=\"text\/css\" \/>\n    <script type=\"text\/javascript\" src=\"https:\/\/gsma.tfaforms.net\/wForms\/3.11\/js\/wforms.js?v=1788154697\"><\/script>\n    <script type=\"text\/javascript\" src=\"https:\/\/gsma.tfaforms.net\/js\/wforms_session_errors_aria.js?v=1788154697\" defer><\/script>\n    <script type=\"text\/javascript\">\n        if(wFORMS.behaviors.prefill) wFORMS.behaviors.prefill.skip = true;\n    <\/script>\n    <link rel=\"stylesheet\" type=\"text\/css\" href=\"https:\/\/gsma.tfaforms.net\/css\/kalendae.css\" \/>\n\t<script type=\"text\/javascript\" src=\"https:\/\/gsma.tfaforms.net\/js\/kalendae\/kalendae.standalone.a11y.min.js\" ><\/script>\n\t<script type=\"text\/javascript\" src=\"https:\/\/gsma.tfaforms.net\/wForms\/3.11\/js\/wforms_calendar.js\"><\/script>\n    <script type=\"text\/javascript\" src=\"https:\/\/gsma.tfaforms.net\/wForms\/3.11\/js\/localization-en_US.js?v=1788154697\"><\/script>\n<link href=\"https:\/\/cdnjs.cloudflare.com\/ajax\/libs\/font-awesome\/4.4.0\/css\/font-awesome.min.css\" rel=\"stylesheet\" type=\"text\/css\" \/>\n    <script>\n        var FAoldJQ;\n        if (typeof $ != 'undefined' && $.noConflict) FAoldJQ = $.noConflict(true);\n    <\/script>\n    <script src=\"https:\/\/gsma.tfaforms.net\/dist\/jquery\/jquery.a7691f40d21027ec7d86.js\"><\/script>\n    <script src=\"https:\/\/gsma.tfaforms.net\/js\/typeahead\/v1.2.0\/typeahead.bundle.js\"><\/script>\n    <script>\n        var FA$ = $.noConflict(true);\n        if (FAoldJQ) $ = jQuery = FAoldJQ;\n    <\/script>\n\n<!-- FORM: BODY SECTION -->\n<div class=\"wFormContainer\" >\n    <div class=\"wFormHeader\"><\/div>\n    <style type=\"text\/css\">\n                #tfa_2407,\n                *[id^=\"tfa_2407[\"] {\n                    width: 195px !important;\n                }\n                #tfa_2407-D,\n                *[id^=\"tfa_2407[\"][class~=\"field-container-D\"] {\n                    width: auto !important;\n                }\n            <\/style><div class=\"\"><div class=\"wForm\" id=\"476-WRPR\" data-language=\"en_US\" dir=\"ltr\">\n<div class=\"codesection\" id=\"code-476\"><\/div>\n<form method=\"post\" action=\"https:\/\/gsma.tfaforms.net\/api_v2\/rest\/workflow\/processor\" class=\"hintsBelow labelsAbove\" id=\"476\">\n<div id=\"tfa_4\" class=\"section inline group\">\n<div class=\"oneField field-container-D    \" id=\"tfa_1-D\">\n<label id=\"tfa_1-L\" class=\"label preField reqMark\" for=\"tfa_1\"><b>First Name<\/b><\/label><br><div class=\"inputWrapper\"><input aria-required=\"true\" type=\"text\" id=\"tfa_1\" name=\"tfa_1\" value=\"\" title=\"First Name\" class=\"required\"><\/div>\n<\/div>\n<div class=\"oneField field-container-D    \" id=\"tfa_3-D\">\n<label id=\"tfa_3-L\" class=\"label preField reqMark\" for=\"tfa_3\"><b>Surname&nbsp;<\/b><\/label><br><div class=\"inputWrapper\"><input aria-required=\"true\" type=\"text\" id=\"tfa_3\" name=\"tfa_3\" value=\"\" title=\"Surname \" class=\"required\"><\/div>\n<\/div>\n<\/div>\n<div id=\"tfa_8\" class=\"section inline group\">\n<div class=\"oneField field-container-D    \" id=\"tfa_5-D\">\n<label id=\"tfa_5-L\" class=\"label preField reqMark\" for=\"tfa_5\"><b>Email&nbsp;<\/b><\/label><br><div class=\"inputWrapper\"><input aria-required=\"true\" type=\"text\" id=\"tfa_5\" name=\"tfa_5\" value=\"\" title=\"Email \" class=\"validate-email required\"><\/div>\n<\/div>\n<div class=\"oneField field-container-D    \" id=\"tfa_7-D\">\n<label id=\"tfa_7-L\" class=\"label preField reqMark\" for=\"tfa_7\"><b>Phone number<\/b><\/label><br><div class=\"inputWrapper\"><input aria-required=\"true\" type=\"text\" id=\"tfa_7\" name=\"tfa_7\" value=\"\" title=\"Phone number\" class=\"required\"><\/div>\n<\/div>\n<\/div>\n<div id=\"tfa_2688\" class=\"section inline group\">\n<div class=\"oneField field-container-D    \" id=\"tfa_9-D\">\n<label id=\"tfa_9-L\" class=\"label preField reqMark\" for=\"tfa_9\"><b>Company Name<\/b><\/label><br><div class=\"inputWrapper\"><input aria-required=\"true\" type=\"text\" id=\"tfa_9\" name=\"tfa_9\" value=\"\" title=\"Company Name\" class=\"required\"><\/div>\n<\/div>\n<div class=\"oneField field-container-D    \" id=\"tfa_2687-D\">\n<label id=\"tfa_2687-L\" class=\"label preField reqMark\" for=\"tfa_2687\"><b>Country \/ Region<\/b><\/label><br><div class=\"inputWrapper\">\n<input aria-required=\"true\" type=\"text\" id=\"tfa_2687\" name=\"tfa_2687\" value=\"\" title=\"Country \/ Region\" data-dataset-allow-free-responses=\"0\" data-dataset-clear-cache=\"1\" autocomplete=\"off\" data-dataset-parameters=\"undefined\" data-dataset-timestamp=\"1663825336\" data-dataset-id=\"40d76123-907d-49ee-9e9a-94f77599a4d0\" data-dataset-map=\"\" data-dataset-type=\"salesforce-picklist\" data-dataset-url=\"https:\/\/gsma.tfaforms.net\/api_v2\/datasets\" class=\"required wfAutosuggest\"><i class=\"fa fa-spinner fa-pulse fa-fw tt-spinner\"><\/i><i class=\"fa fa-search tt-search\" aria-hidden=\"true\"><\/i><i class=\"fa fa-times-circle tt-clear no-input\" tabindex=\"0\" aria-label=\"Clear field\" role=\"button\"><\/i>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"oneField field-container-D    \" id=\"tfa_2680-D\" role=\"group\" aria-labelledby=\"tfa_2680-L\" data-tfa-labelledby=\"-L tfa_2680-L\">\n<label id=\"tfa_2680-L\" class=\"label preField reqMark\" data-tfa-check-label-for=\"tfa_2680\" aria-label=\"Can we provide your name to the vendor if required? \u00a0 required\">Can we provide your name to the vendor if required?<\/label><br><div class=\"inputWrapper\"><span id=\"tfa_2680\" class=\"choices vertical required\"><span class=\"oneChoice\"><input type=\"checkbox\" value=\"tfa_2681\" class=\"\" id=\"tfa_2681\" name=\"tfa_2681\" aria-labelledby=\"tfa_2681-L\" data-tfa-labelledby=\"tfa_2680-L tfa_2681-L\" data-tfa-parent-id=\"tfa_2680\"><label class=\"label postField\" id=\"tfa_2681-L\" for=\"tfa_2681\"><span class=\"input-checkbox-faux\"><\/span>No<\/label><\/span><span class=\"oneChoice\"><input type=\"checkbox\" value=\"tfa_2682\" class=\"\" id=\"tfa_2682\" name=\"tfa_2682\" aria-labelledby=\"tfa_2682-L\" data-tfa-labelledby=\"tfa_2680-L tfa_2682-L\" data-tfa-parent-id=\"tfa_2680\"><label class=\"label postField\" id=\"tfa_2682-L\" for=\"tfa_2682\"><span class=\"input-checkbox-faux\"><\/span>Yes<\/label><\/span><\/span><\/div>\n<\/div>\n<div class=\"oneField field-container-D    \" id=\"tfa_2683-D\" role=\"group\" aria-labelledby=\"tfa_2683-L\" data-tfa-labelledby=\"-L tfa_2683-L\">\n<label id=\"tfa_2683-L\" class=\"label preField reqMark\" data-tfa-check-label-for=\"tfa_2683\" aria-label=\"Do you want to be publicly acknowledged? \u00a0 required\">Do you want to be publicly acknowledged?<\/label><br><div class=\"inputWrapper\"><span id=\"tfa_2683\" class=\"choices vertical required\"><span class=\"oneChoice\"><input type=\"checkbox\" value=\"tfa_2684\" class=\"\" id=\"tfa_2684\" name=\"tfa_2684\" aria-labelledby=\"tfa_2684-L\" data-tfa-labelledby=\"tfa_2683-L tfa_2684-L\" data-tfa-parent-id=\"tfa_2683\"><label class=\"label postField\" id=\"tfa_2684-L\" for=\"tfa_2684\"><span class=\"input-checkbox-faux\"><\/span>No<\/label><\/span><span class=\"oneChoice\"><input type=\"checkbox\" value=\"tfa_2685\" class=\"\" id=\"tfa_2685\" name=\"tfa_2685\" aria-labelledby=\"tfa_2685-L\" data-tfa-labelledby=\"tfa_2683-L tfa_2685-L\" data-tfa-parent-id=\"tfa_2683\"><label class=\"label postField\" id=\"tfa_2685-L\" for=\"tfa_2685\"><span class=\"input-checkbox-faux\"><\/span>Yes<\/label><\/span><\/span><\/div>\n<\/div>\n<div id=\"tfa_2421\" class=\"section group\">\n<label class=\"label preField\" id=\"tfa_2421-L\"><b>Vulnerability details<\/b><\/label><br><div class=\"oneField field-container-D    \" id=\"tfa_2412-D\">\n<label id=\"tfa_2412-L\" class=\"label preField reqMark\" for=\"tfa_2412\">Title of vulnerability<\/label><br><div class=\"inputWrapper\"><textarea aria-required=\"true\" id=\"tfa_2412\" name=\"tfa_2412\" title=\"Title of vulnerability\" class=\"required\"><\/textarea><\/div>\n<\/div>\n<div class=\"oneField field-container-D    \" id=\"tfa_2414-D\">\n<label id=\"tfa_2414-L\" class=\"label preField reqMark\" for=\"tfa_2414\">Description of vulnerability<\/label><br><div class=\"inputWrapper\">\n<textarea aria-required=\"true\" aria-describedby=\"tfa_2414-HH\" id=\"tfa_2414\" name=\"tfa_2414\" title=\"Description of vulnerability\" class=\"required\"><\/textarea><span class=\"field-hint-inactive\" id=\"tfa_2414-H\"><span id=\"tfa_2414-HH\" class=\"hint\">Details such as: <br>\n\n* Preconditions\/Assumptions for the attack.\n<br>\n* Traffic flows (if applicable).\n<br>\n* Effect and impact.\n<br>\n* Relevant specification clause numbers (if applicable).<\/span><\/span>\n<\/div>\n<\/div>\n<div class=\"oneField field-container-D    \" id=\"tfa_2416-D\">\n<label id=\"tfa_2416-L\" class=\"label preField reqMark\" for=\"tfa_2416\">Product or Service<\/label><br><div class=\"inputWrapper\"><textarea aria-required=\"true\" id=\"tfa_2416\" name=\"tfa_2416\" title=\"Product or Service\" class=\"required\"><\/textarea><\/div>\n<\/div>\n<div class=\"oneField field-container-D    \" id=\"tfa_2418-D\">\n<label id=\"tfa_2418-L\" class=\"label preField reqMark\" for=\"tfa_2418\">Date vulnerability found<\/label><br><div class=\"inputWrapper\"><input aria-required=\"true\" type=\"text\" id=\"tfa_2418\" name=\"tfa_2418\" value=\"\" autocomplete=\"off\" min=\"-|1_Year{}\" max=\"+|1_Month{}\" title=\"Date vulnerability found\" class=\"validate-datecal required\"><\/div>\n<\/div>\n<div class=\"oneField field-container-D    \" id=\"tfa_2420-D\" role=\"radiogroup\" aria-labelledby=\"tfa_2420-L\" data-tfa-labelledby=\"-L tfa_2420-L\">\n<label id=\"tfa_2420-L\" class=\"label preField reqMark\" data-tfa-check-label-for=\"tfa_2420\">Is this vulnerability still live?&nbsp;<\/label><br><div class=\"inputWrapper\"><span id=\"tfa_2420\" class=\"choices vertical required\"><span class=\"oneChoice\"><input type=\"radio\" value=\"tfa_2422\" class=\"\" id=\"tfa_2422\" name=\"tfa_2420\" aria-required=\"true\" aria-labelledby=\"tfa_2422-L\" data-tfa-labelledby=\"tfa_2420-L tfa_2422-L\" data-tfa-parent-id=\"tfa_2420\"><label class=\"label postField\" id=\"tfa_2422-L\" for=\"tfa_2422\"><span class=\"input-radio-faux\"><\/span>Yes<\/label><\/span><span class=\"oneChoice\"><input type=\"radio\" value=\"tfa_2423\" class=\"\" id=\"tfa_2423\" name=\"tfa_2420\" aria-required=\"true\" aria-labelledby=\"tfa_2423-L\" data-tfa-labelledby=\"tfa_2420-L tfa_2423-L\" data-tfa-parent-id=\"tfa_2420\"><label class=\"label postField\" id=\"tfa_2423-L\" for=\"tfa_2423\"><span class=\"input-radio-faux\"><\/span>No<\/label><\/span><\/span><\/div>\n<\/div>\n<div class=\"oneField field-container-D    \" id=\"tfa_2424-D\" role=\"radiogroup\" aria-labelledby=\"tfa_2424-L\" data-tfa-labelledby=\"-L tfa_2424-L\">\n<label id=\"tfa_2424-L\" class=\"label preField reqMark\" data-tfa-check-label-for=\"tfa_2424\">Do you believe the vulnerability is being currently exploited?<\/label><br><div class=\"inputWrapper\"><span id=\"tfa_2424\" class=\"choices vertical required\"><span class=\"oneChoice\"><input type=\"radio\" value=\"tfa_2425\" class=\"\" id=\"tfa_2425\" name=\"tfa_2424\" aria-required=\"true\" data-conditionals=\"#tfa_2679\" aria-labelledby=\"tfa_2425-L\" data-tfa-labelledby=\"tfa_2424-L tfa_2425-L\" data-tfa-parent-id=\"tfa_2424\"><label class=\"label postField\" id=\"tfa_2425-L\" for=\"tfa_2425\"><span class=\"input-radio-faux\"><\/span>Yes<\/label><\/span><span class=\"oneChoice\"><input type=\"radio\" value=\"tfa_2426\" class=\"\" id=\"tfa_2426\" name=\"tfa_2424\" aria-required=\"true\" aria-labelledby=\"tfa_2426-L\" data-tfa-labelledby=\"tfa_2424-L tfa_2426-L\" data-tfa-parent-id=\"tfa_2424\"><label class=\"label postField\" id=\"tfa_2426-L\" for=\"tfa_2426\"><span class=\"input-radio-faux\"><\/span>No<\/label><\/span><\/span><\/div>\n<\/div>\n<div class=\"oneField field-container-D    \" id=\"tfa_2679-D\">\n<label id=\"tfa_2679-L\" class=\"label preField reqMark\" for=\"tfa_2679\">Please can you explain further:<\/label><br><div class=\"inputWrapper\"><textarea aria-required=\"true\" id=\"tfa_2679\" name=\"tfa_2679\" data-condition=\"`#tfa_2425`\" title=\"Please can you explain further:\" class=\"required\"><\/textarea><\/div>\n<\/div>\n<div class=\"oneField field-container-D    \" id=\"tfa_2427-D\" role=\"radiogroup\" aria-labelledby=\"tfa_2427-L\" data-tfa-labelledby=\"-L tfa_2427-L\">\n<label id=\"tfa_2427-L\" class=\"label preField reqMark\" data-tfa-check-label-for=\"tfa_2427\">Probability of reproduction of vulnerability:<\/label><br><div class=\"inputWrapper\"><span id=\"tfa_2427\" class=\"choices vertical required\"><span class=\"oneChoice\"><input type=\"radio\" value=\"tfa_2428\" class=\"\" id=\"tfa_2428\" name=\"tfa_2427\" aria-required=\"true\" aria-labelledby=\"tfa_2428-L\" data-tfa-labelledby=\"tfa_2427-L tfa_2428-L\" data-tfa-parent-id=\"tfa_2427\"><label class=\"label postField\" id=\"tfa_2428-L\" for=\"tfa_2428\"><span class=\"input-radio-faux\"><\/span>Always<\/label><\/span><span class=\"oneChoice\"><input type=\"radio\" value=\"tfa_2429\" class=\"\" id=\"tfa_2429\" name=\"tfa_2427\" aria-required=\"true\" aria-labelledby=\"tfa_2429-L\" data-tfa-labelledby=\"tfa_2427-L tfa_2429-L\" data-tfa-parent-id=\"tfa_2427\"><label class=\"label postField\" id=\"tfa_2429-L\" for=\"tfa_2429\"><span class=\"input-radio-faux\"><\/span>Often<\/label><\/span><span class=\"oneChoice\"><input type=\"radio\" value=\"tfa_2430\" class=\"\" id=\"tfa_2430\" name=\"tfa_2427\" aria-required=\"true\" aria-labelledby=\"tfa_2430-L\" data-tfa-labelledby=\"tfa_2427-L tfa_2430-L\" data-tfa-parent-id=\"tfa_2427\"><label class=\"label postField\" id=\"tfa_2430-L\" for=\"tfa_2430\"><span class=\"input-radio-faux\"><\/span>Rarely<\/label><\/span><\/span><\/div>\n<\/div>\n<div class=\"oneField field-container-D    \" id=\"tfa_2431-D\">\n<label id=\"tfa_2431-L\" class=\"label preField reqMark\" for=\"tfa_2431\">Possible threat caused by the vulnerability<\/label><br><div class=\"inputWrapper\"><textarea aria-required=\"true\" id=\"tfa_2431\" name=\"tfa_2431\" title=\"Possible threat caused by the vulnerability\" class=\"required\"><\/textarea><\/div>\n<\/div>\n<div class=\"oneField field-container-D    \" id=\"tfa_2432-D\" role=\"radiogroup\" aria-labelledby=\"tfa_2432-L\" data-tfa-labelledby=\"-L tfa_2432-L\">\n<label id=\"tfa_2432-L\" class=\"label preField reqMark\" data-tfa-check-label-for=\"tfa_2432\">Do you intend to let us review the vulnerability before going public?<\/label><br><div class=\"inputWrapper\"><span id=\"tfa_2432\" class=\"choices vertical required\"><span class=\"oneChoice\"><input type=\"radio\" value=\"tfa_2433\" class=\"\" id=\"tfa_2433\" name=\"tfa_2432\" aria-required=\"true\" aria-labelledby=\"tfa_2433-L\" data-tfa-labelledby=\"tfa_2432-L tfa_2433-L\" data-tfa-parent-id=\"tfa_2432\"><label class=\"label postField\" id=\"tfa_2433-L\" for=\"tfa_2433\"><span class=\"input-radio-faux\"><\/span>Yes<\/label><\/span><span class=\"oneChoice\"><input type=\"radio\" value=\"tfa_2434\" class=\"\" id=\"tfa_2434\" name=\"tfa_2432\" aria-required=\"true\" aria-labelledby=\"tfa_2434-L\" data-tfa-labelledby=\"tfa_2432-L tfa_2434-L\" data-tfa-parent-id=\"tfa_2432\"><label class=\"label postField\" id=\"tfa_2434-L\" for=\"tfa_2434\"><span class=\"input-radio-faux\"><\/span>No<\/label><\/span><\/span><\/div>\n<\/div>\n<div class=\"oneField field-container-D    \" id=\"tfa_2435-D\">\n<label id=\"tfa_2435-L\" class=\"label preField reqMark\" for=\"tfa_2435\">To what other organisation(s) has the vulnerability been reported?<\/label><br><div class=\"inputWrapper\"><textarea aria-required=\"true\" id=\"tfa_2435\" name=\"tfa_2435\" title=\"To what other organisation(s) has the vulnerability been reported?\" class=\"required\"><\/textarea><\/div>\n<\/div>\n<\/div>\n<div class=\"oneField field-container-D    \" id=\"tfa_2686-D\">\n<label id=\"tfa_2686-L\" class=\"label preField reqMark\" for=\"tfa_2686\"><span style=\"color: rgb(8, 7, 7); font-family: -apple-system, BlinkMacSystemFont, &quot;Segoe UI&quot;, Roboto, Helvetica, Arial, sans-serif, &quot;Apple Color Emoji&quot;, &quot;Segoe UI Emoji&quot;, &quot;Segoe UI Symbol&quot;; font-size: 14px;\">Can you provide any PoC Code, Screenshots or Http requests etc?&nbsp;<\/span><span style=\"color: rgb(8, 7, 7); font-family: -apple-system, BlinkMacSystemFont, &quot;Segoe UI&quot;, Roboto, Helvetica, Arial, sans-serif, &quot;Apple Color Emoji&quot;, &quot;Segoe UI Emoji&quot;, &quot;Segoe UI Symbol&quot;; font-size: 14px;\">(Please email attachments to&nbsp;<\/span><a target=\"_blank\" href=\"mailto:security@gsma.com\" rel=\"noopener\" style=\"background-color: rgb(255, 255, 255); color: var(--lwc-brandTextLink,rgb(1, 118, 211)); text-decoration-line: none; font-family: -apple-system, BlinkMacSystemFont, &quot;Segoe UI&quot;, Roboto, Helvetica, Arial, sans-serif, &quot;Apple Color Emoji&quot;, &quot;Segoe UI Emoji&quot;, &quot;Segoe UI Symbol&quot;; font-size: 14px;\">security@gsma.com<\/a>)<\/label><br><div class=\"inputWrapper\"><input aria-required=\"true\" type=\"text\" id=\"tfa_2686\" name=\"tfa_2686\" value=\"\" title=\"Can you provide any PoC Code, Screenshots or Http requests etc? (Please email attachments to security@gsma.com)\" class=\"required\"><\/div>\n<\/div>\n<div class=\"oneField field-container-D    \" id=\"tfa_280-D\" role=\"group\" aria-labelledby=\"tfa_280-L\" data-tfa-labelledby=\"-L tfa_280-L\">\n<label id=\"tfa_280-L\" class=\"label preField \" data-tfa-check-label-for=\"tfa_280\"><b>EMAIL CONSENT<\/b><\/label><br><div class=\"inputWrapper\"><span id=\"tfa_280\" class=\"choices vertical \"><span class=\"oneChoice\"><input type=\"checkbox\" value=\"tfa_281\" class=\"\" id=\"tfa_281\" name=\"tfa_281\" aria-labelledby=\"tfa_281-L\" data-tfa-labelledby=\"tfa_280-L tfa_281-L\" data-tfa-parent-id=\"tfa_280\"><label class=\"label postField\" id=\"tfa_281-L\" for=\"tfa_281\"><span class=\"input-checkbox-faux\"><\/span><span style=\"color: rgb(82, 81, 81); font-size: 15px;\">To ensure you stay up-to-date on the latest developments in the mobile industry, the GSMA would like to send you information about events, products, services and initiatives, as well as industry news. Please subscribe by ticking this box; once subscribed, you can tailor what you receive from us at any time, or unsubscribe, should you wish.<\/span><\/label><\/span><\/span><\/div>\n<\/div>\n<div id=\"tfa_2401\" class=\"section group\">\n<input type=\"hidden\" id=\"tfa_2403\" name=\"tfa_2403\" value=\"utm_content__c\" class=\"\"><input type=\"hidden\" id=\"tfa_2404\" name=\"tfa_2404\" value=\"utm_source__c\" class=\"\"><input type=\"hidden\" id=\"tfa_2405\" name=\"tfa_2405\" value=\"utm_campaign__c\" class=\"\"><input type=\"hidden\" id=\"tfa_2406\" name=\"tfa_2406\" value=\"utm_medium__c\" class=\"\"><input type=\"hidden\" id=\"tfa_2407\" name=\"tfa_2407\" value=\"UA-XXXXXX-X\" class=\"calc-GOOGLEACCOUNTID\">\n<\/div>\n<div class=\"oneField field-container-D     wf-acl-hidden\" id=\"tfa_2678-D\">\n<label id=\"tfa_2678-L\" class=\"label preField \" for=\"tfa_2678\">Address<\/label><br><div class=\"inputWrapper\"><input type=\"text\" id=\"tfa_2678\" name=\"tfa_2678\" value=\"\" title=\"Address\" class=\"validate-custom \/^\\s*$\"><\/div>\n<\/div>\n<div class=\"actions\" id=\"476-A\" data-contentid=\"submit_button\">\n<div id=\"google-captcha\" style=\"display: none\">\n<br><div class=\"captcha\">\n<div class=\"oneField\">\n<div class=\"g-recaptcha\" id=\"g-recaptcha-render-div\"><\/div>\n<div class=\"g-captcha-error\"><\/div>\n<br>\n<\/div>\n<div class=\"captchaHelp\">reCAPTCHA helps prevent automated form spam.<br>\n<\/div>\n<div id=\"disabled-explanation\" class=\"captchaHelp\" style=\"display: none\">The submit button will be disabled until you complete the CAPTCHA.<\/div>\n<\/div>\n<\/div>\n<input type=\"submit\" data-label=\"Submit\" class=\"primaryAction\" id=\"submit_button\" value=\"Submit\">\n<\/div>\n<div style=\"clear:both\"><\/div>\n<input type=\"hidden\" value=\"515-abbe66d76461f25ca1994855519ee10a\" name=\"tfa_dbCounters\" id=\"tfa_dbCounters\" autocomplete=\"off\"><input type=\"hidden\" value=\"476\" name=\"tfa_dbFormId\" id=\"tfa_dbFormId\"><input type=\"hidden\" value=\"\" name=\"tfa_dbResponseId\" id=\"tfa_dbResponseId\"><input type=\"hidden\" value=\"142fbcdf9865d98d473dcd88c3d2602b\" name=\"tfa_dbControl\" id=\"tfa_dbControl\"><input type=\"hidden\" value=\"\" name=\"tfa_dbWorkflowSessionUuid\" id=\"tfa_dbWorkflowSessionUuid\"><input type=\"hidden\" value=\"1788154697\" name=\"tfa_dbTimeStarted\" id=\"tfa_dbTimeStarted\" autocomplete=\"off\"><input type=\"hidden\" value=\"35\" name=\"tfa_dbVersionId\" id=\"tfa_dbVersionId\"><input type=\"hidden\" value=\"\" name=\"tfa_switchedoff\" id=\"tfa_switchedoff\">\n<\/form>\n<\/div><\/div><div class=\"wFormFooter\"><p class=\"supportInfo\"><br><\/p><\/div>\n  <p class=\"supportInfo\" >\n      <\/p>\n <\/div>\n\n<script\n    id=\"analytics-collector-script\"\n    type=\"text\/javascript\"\n    src=\"https:\/\/gsma.tfaforms.net\/dist\/analytics\/data-collector.f9f54c12ade21135b7c2.js\"\n    data-customer-id=\"2273\"\n    data-endpoint=\"https:\/\/analytics.formassembly.com\/v1\/traces\"\n><\/script>\n\n<\/p>\n<p>\n<\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>There are two ways of submitting to the GSMA Coordinated Vulnerability Disclosure programme. You can download the submission form in Microsoft Word or Text version format and send it back to the GSMA, or you can fill the online form below.&nbsp; We request reporters of vulnerabilities to describe the vulnerability on the submission form, including: [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_oasis_is_in_workflow":0,"_oasis_original":0,"_oasis_task_priority":"","footnotes":""},"tags":[],"class_list":["post-3552","page","type-page","status-publish","hentry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v24.3 (Yoast SEO v24.3) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>CVD Programme Submit Research<\/title>\n<meta name=\"description\" content=\"Submit your vulnerability research to GSMA experts.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/cvd-submit-a-vulnerability\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CVD Programme Submit Research\" \/>\n<meta property=\"og:description\" content=\"Submit your vulnerability research to GSMA experts.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/cvd-submit-a-vulnerability\/\" \/>\n<meta property=\"og:site_name\" content=\"Security\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-17T13:18:35+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"3 minutes\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"CVD Programme Submit Research","description":"Submit your vulnerability research to GSMA experts.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/cvd-submit-a-vulnerability\/","og_locale":"en_GB","og_type":"article","og_title":"CVD Programme Submit Research","og_description":"Submit your vulnerability research to GSMA experts.","og_url":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/cvd-submit-a-vulnerability\/","og_site_name":"Security","article_modified_time":"2026-08-17T13:18:35+00:00","twitter_card":"summary_large_image","twitter_misc":{"Estimated reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/cvd-submit-a-vulnerability\/","url":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/cvd-submit-a-vulnerability\/","name":"CVD Programme Submit Research","isPartOf":{"@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/#website"},"datePublished":"2022-01-07T17:52:38+00:00","dateModified":"2026-08-17T13:18:35+00:00","description":"Submit your vulnerability research to GSMA experts.","inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/cvd-submit-a-vulnerability\/"]}]},{"@type":"WebSite","@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/#website","url":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/","name":"Security","description":"GSMA Security","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"}]}},"_links":{"self":[{"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/pages\/3552","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/comments?post=3552"}],"version-history":[{"count":27,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/pages\/3552\/revisions"}],"predecessor-version":[{"id":14569,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/pages\/3552\/revisions\/14569"}],"wp:attachment":[{"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/media?parent=3552"}],"wp:term":[{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/tags?post=3552"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}