{"id":"3d6114ec-05df-466f-a3c5-0e06a9bd942d","engagementId":"9c549241-0120-480e-b634-d71fecfe9338","data":{"brief":{"id":"1801b802-9761-4c24-b7e3-e8f5a338d79e","name":"Arlo Kudos Rewards","tagline":"Arlo Kudos Rewards Program","description":"\u003ch1\u003eAbout Arlo Kudos Rewards Program\u003c/h1\u003e\n\n\u003cp\u003eThis program encourages and rewards contributions by developers and security researchers who help make Arlo’s products more secure. Arlo provides kudos points for qualifying vulnerability submissions to this program. In addition to this program Arlo offers a Cash Reward Program that includes large payouts for eligible High Impact Submissions. If you believe you have found a vulnerability that meets the criteria for a cash reward please submit it to the \u003ca href=\"https://bugcrowd.com/arlo\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eArlo Cash Rewards Program\u003c/a\u003e.\u003c/p\u003e\n\n\u003ch3\u003eIn Scope\u003c/h3\u003e\n\n\u003cp\u003eEverything not covered by the \u003ca href=\"https://www.bugcrowd.com/arlo\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eArlo Cash Rewards Program\u003c/a\u003e\u003c/p\u003e","industryTagId":null,"targetsOverview":"\u003ch3\u003ePriority and Reward Guidelines\u003c/h3\u003e\n\n\u003cp\u003eArlo issues kudos points for any issue deemed unique, valid, and at least a P4 in Bugcrowd’s \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eVulnerability Rating Taxonomy (VRT)\u003c/a\u003e.\u003cbr\u003e\n​\u003cbr\u003e\nAll issues around login and access are of particular concern. Most login submissions classified as P5s will likely be elevated to P4 or greater issues.\u003cbr\u003e\n​\u003c/p\u003e\n\n\u003ch3\u003eProgram Exclusions\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eDuplicate reports of security issues, including security issues that have already been identified internally\u003c/li\u003e\n\u003cli\u003eAutomated scanning attacks\u003c/li\u003e\n\u003cli\u003eDistributed Denial of Service attacks and Denial of Service attacks\u003c/li\u003e\n\u003cli\u003eUI bugs, UX bugs, and spelling mistakes\u003c/li\u003e\n\u003cli\u003eViolations of licenses or other restrictions applicable to any vendor's product\u003c/li\u003e\n\u003cli\u003eTheoretical security issues with no realistic exploit scenario(s) or attack surfaces, or issues that would require complex end user interactions to be exploited, may be excluded\u003c/li\u003e\n\u003cli\u003eDiscovery of any in-use service whose version contains known vulnerabilities (such as a specific version of OpenSSL, Apache, Tomcat, etc.) without a demonstration of intrusion, information retrieval, or service disruption using that vulnerability\n​\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eLegal Terms and Conditions\u003c/h3\u003e\n\n\u003cp\u003eIn addition to these Terms and Conditions regarding the Arlo Responsible Disclosure Program (the \"Program\"), there may be additional restrictions depending upon applicable local laws.\u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003eThe parties to this Agreement are you and Arlo Technologies, Inc.\u003c/li\u003e\n\u003cli\u003e\"Arlo\" refers to Arlo Technologies, Inc. and its affiliates.\u003c/li\u003e\n\u003cli\u003eBy submitting the security bug, you affirm that you have not disclosed and agree that you will not disclose the security bug to anyone other than Arlo. Absent Arlo's prior written consent, any disclosure outside of this process would violate this Agreement. You agree that money damages may not be a sufficient remedy for a breach of this paragraph by you and that Arlo will be entitled to specific performance as a remedy for any such breach. Such remedy will not be deemed to be the exclusive remedy for any such breach but will be in addition to all other remedies available at law or equity to Arlo.\u003c/li\u003e\n\u003cli\u003eBy submitting information about a potential security bug, you are granting Arlo a worldwide, royalty-free, non-exclusive license to use your submission for the purpose of addressing security bugs in Arlo’s products and services.\u003c/li\u003e\n\u003cli\u003eIn the event of substantially duplicate submissions, Arlo may at its discretion provide a Reward only for the earliest received submission. Eligibility for Rewards, determination of the recipients, and amount of Reward is at the discretion of Arlo.\u003c/li\u003e\n\u003cli\u003eIf issues reported to our bug bounty program affect a third party or another vendor, Arlo reserves the right to forward details of the issue along to the party without further discussion with the researcher.\u003c/li\u003e\n\u003cli\u003eYou are responsible for all taxes associated with and imposed on any Reward you may receive from Arlo.\u003c/li\u003e\n\u003cli\u003eYou may only exploit, investigate, or target security bugs against your own accounts and/or your own devices. Testing must not violate any law, or disrupt or compromise any data or access data that is not yours; intentional access of customer data other than your own is prohibited.\u003c/li\u003e\n\u003cli\u003eIf you inadvertently access proprietary customer, employee, or business related information during your testing, the information must not be used, disclosed, stored, or recorded in any way. Inadvertent access of the data must be declared within your submission.\u003c/li\u003e\n\u003cli\u003eYour testing activities must not negatively impact Arlo, Arlo’s products or services generally, or Arlo's online environment availability or performance.\u003c/li\u003e\n\u003cli\u003eArlo may choose not to remediate at its sole discretion.\u003c/li\u003e\n\u003cli\u003eThis Agreement constitutes the entire agreement of the parties with respect to the items listed above. This Agreement is covered by California law. This Agreement may be amended or modified only by a subsequent agreement in writing.\u003c/li\u003e\n\u003cli\u003eIf any portion of this Agreement is found to be illegal or unenforceable, then the parties will be relieved of their responsibilities arising under such portion, but only to the extent that such portion is illegal or unenforceable.\u003c/li\u003e\n\u003cli\u003eYou must not be the author of the code with the vulnerability.\u003c/li\u003e\n\u003cli\u003eYou must not be an Arlo employee, contractor, or a family member of an employee or contractor.\n​\n\u003cem\u003eARLO RESERVES THE RIGHT TO MODIFY OR CANCEL THE ARLO RESPONSIBLE DISCLOSURE PROGRAM AT ANY TIME WITHOUT NOTICE. ALL PARTICIPANTS AND SUBMISSIONS ARE STRICTLY VOLUNTARY. THIS OFFER IS VOID WHERE PROHIBITED BY LAW AND IN PARTICIPATING, YOU MUST NOT VIOLATE ANY LAW. YOU ALSO MUST NOT DISRUPT ANY SERVICE OR COMPROMISE ANYONE’S DATA.\u003c/em\u003e\n​\n### Rules\n​\n​\nThis bounty follows Bugcrowd’s \u003ca href=\"https://researcherdocs.bugcrowd.com/docs/disclosure\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ePublic Disclosure Policy\u003c/a\u003e.\n​\nRequests to disclose the results of a submission will be considered on a case by case basis and require explicit prior written consent from Arlo. \u003c/li\u003e\n\u003c/ol\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[],"resources":[],"engagement":{"id":"9c549241-0120-480e-b634-d71fecfe9338","code":"arlokudos","state":"in_progress","endsAt":null,"bountyId":"a3a078d6-c960-48ef-8e6e-14ed9116eebc","startsAt":"2018-05-16T19:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":null,"methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/9fbb/8c88/26d3223f/d37417924219f5a94c4832c96d118948_arlo.jpg","logoBackgroundColor":"#04ab51","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2018-05-16T19:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/arlokudos","changelogs":"/engagements/arlokudos/changelog","submissions":null,"announcements":"/engagements/arlokudos/announcements","hallOfFame":"/engagements/arlokudos/hall_of_fames","crowdstream":"/engagements/arlokudos/crowdstream"},"announcementsCount":2,"knownIssuesEnabled":false,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/arlokudos/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=arlokudos\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/arlokudos/engagement_subscribers","engagementChangelogsUrl":"/engagements/arlokudos/changelog","publishedAt":"2018-05-08T17:49:18.678Z","engagementChangelogUrl":"/engagements/arlokudos/changelog/3d6114ec-05df-466f-a3c5-0e06a9bd942d","createUserFeedbacksUrl":"/engagements/arlokudos/feedbacks","engagementCrowdstreamUrl":"/engagements/arlokudos/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}