{"id":"bafce899-ed68-4708-b2dc-1c8485d69024","engagementId":"f50364ea-b2d0-4915-bf3e-7c26e172fca1","data":{"brief":{"id":"b5537dab-21c2-4da8-bc69-66a1ec9b0fb8","name":"Dell Technologies' Products Bug Bounty Program","tagline":"Submit your finding to Dell's Product Bug Bounty Program","description":"\u003ch1\u003eDell Technologies Product Bug Bounty Program\u003c/h1\u003e\n\n\u003cp\u003eDell Technologies (\"Dell\") recognizes the value of the security community to create a more secure world and welcomes the opportunity to collaborate with community members who share this common goal.\u003c/p\u003e\n\n\u003cp\u003eThis Bug Bounty Program applies to security vulnerabilities identified within Dell-branded or currently supported products. Please carefully review the inclusions and exclusions detailed in the sections below.\u003c/p\u003e\n\n\u003ch1\u003eTriage Process - Please Read First\u003c/h1\u003e\n\n\u003cp\u003eIn order for Dell to properly reproduce a security report, it is \u003cstrong\u003erequired\u003c/strong\u003e to enter the Product Name and Version Number of the vulnerable device in the \u003cstrong\u003eURL / Location of vulnerability\u003c/strong\u003e field. Reports that do not have this information will be rejected. \u003c/p\u003e\n\n\u003cp\u003eSubmissions with Blockers on them for longer than 5 business days will closed as \u003cem\u003eNot Applicable\u003c/em\u003e.\u003c/p\u003e\n\n\u003cp\u003eOnce a Product and Version are confirmed by Dell, a report will be moved to \u003cem\u003eTriaged\u003c/em\u003e to validate the report and assign an Impact. In order to help expedite the Triage process, please ensure reports have:\u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003eBulleted, step-by-step reproduction instructions\u003c/li\u003e\n\u003cli\u003eAttach any scripts used in the exploit\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"6825f068-7447-450e-9134-158ae26e18d4","targetsOverview":"\u003ch2\u003eTarget Information\u003c/h2\u003e\n\n\u003ch2\u003eProducts:\u003c/h2\u003e\n\n\u003cp\u003eDell does not provide products for security testing.  Any testing by the researcher should only be against Dell products which you have authorized access.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eFocus Areas\u003c/h2\u003e\n\n\u003cp\u003eWe are looking for any vulnerability that could negatively affect the security of our company and our customers. The main categories of vulnerabilities that we look for are the following:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eRemote code execution as root\u003c/li\u003e\n\u003cli\u003eRemote root login\u003c/li\u003e\n\u003cli\u003eRemote configuration injections\u003c/li\u003e\n\u003cli\u003eLocal privilege escalations\u003c/li\u003e\n\u003cli\u003eUnauthorized access to sensitive data\u003c/li\u003e\n\u003cli\u003eDirect exposure of highly sensitive customer data to unauthorized parties, for example:\n\n\u003cul\u003e\n\u003cli\u003eDevice secrets\u003c/li\u003e\n\u003cli\u003eCryptographic keys\u003c/li\u003e\n\u003cli\u003eCustomer credentials or PII\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eCross-site Scripting (XSS)\u003c/li\u003e\n\u003cli\u003eCross-site Request Forgery (CSRF)\u003c/li\u003e\n\u003cli\u003eServer-Side Request Forgery (SSRF)\u003c/li\u003e\n\u003cli\u003eSQL Injection\u003c/li\u003e\n\u003cli\u003eRemote Code Execution (RCE)\u003c/li\u003e\n\u003cli\u003eXML External Entity Injection (XXE) with significant impact\u003c/li\u003e\n\u003cli\u003eAccess Control Issues\u003c/li\u003e\n\u003cli\u003eAuthentication Bypass Issues\u003c/li\u003e\n\u003cli\u003eAuthorization Flaws\u003c/li\u003e\n\u003cli\u003ePrivilege Escalation\u003c/li\u003e\n\u003cli\u003eDirectory Traversal Issues\u003c/li\u003e\n\u003cli\u003eSensitive Information Disclosure\u003c/li\u003e\n\u003cli\u003eData Exposure\u003c/li\u003e\n\u003cli\u003eBusiness Logic Vulnerabilities\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eExcluded Submission Types\u003c/h3\u003e\n\n\u003cp\u003e\u003cem\u003eThis program follows the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e with some additional submission types we consider to be excluded below. Dell will not reward points for the following (including but not limited to) submission types: \u003c/em\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eApplication Installation to Insecure User Controlled Path\u003c/li\u003e\n\u003cli\u003eOut of date software versions\u003c/li\u003e\n\u003cli\u003eReports for assets that are vulnerable to CVEs or 0-days which are less than 30 days since initial publication (CVE \u003ca href=\"https://nvd.nist.gov/vuln/vulnerability-status\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eList Status\u003c/a\u003e of PUBLISHED) will be eligible for reward only if we act based on the report. The report will not be eligible for reward if the asset was previously reported, and remediation has been planned.\u003c/li\u003e\n\u003cli\u003eNo rate limiting or CAPTCHA\u003c/li\u003e\n\u003cli\u003eSubmissions for 3rd party code where Dell is not responsible for the code\u003c/li\u003e\n\u003cli\u003eAttacks requiring physical or administrative access to Dell products or systems\u003c/li\u003e\n\u003cli\u003ePhysical tampering of our hardware devices\u003c/li\u003e\n\u003cli\u003eAny code execution requires full admin privileges to exploit on the Dell products\u003c/li\u003e\n\u003cli\u003eDisclosure of known public files or directories, (e.g. robots.txt)\u003c/li\u003e\n\u003cli\u003eClickjacking and issues only exploitable through clickjacking\u003c/li\u003e\n\u003cli\u003eLogin or Forgot Password page brute force and account lockout not enforced\u003c/li\u003e\n\u003cli\u003eExposure of API keys with no security impact, or where the only impact is exhausting of API quotas\u003c/li\u003e\n\u003cli\u003eStack traces displayed on error pages instead of generic error messages\u003c/li\u003e\n\u003cli\u003eComponent or technology (e.g. PHP, ASP.NET, etc.) usage is revealed\u003c/li\u003e\n\u003cli\u003eApplication allowing username enumeration or user email enumeration\u003c/li\u003e\n\u003cli\u003eLogin or Forgot Password page brute force, account lockout not enforced, or insufficient password strength requirements\u003c/li\u003e\n\u003cli\u003eMalicious file uploads not affecting application server\u003c/li\u003e\n\u003cli\u003eCookies not set with HTTPOnly or secure flag\u003c/li\u003e\n\u003cli\u003eAny missing defense-in-depth security measures which cannot be exploited without the existence of some other weakness\u003c/li\u003e\n\u003cli\u003eReports for assets that are vulnerable to recent CVEs or 0-days will be eligible for reward only if we act based on the report. The report may not be eligible for reward if the asset previously reported and remediation has been planned.\u003c/li\u003e\n\u003cli\u003eDenial of service (DoS) attacks\u003c/li\u003e\n\u003cli\u003eFindings as reported by automated tools without additional analysis as to how and what is vulnerable\u003c/li\u003e\n\u003cli\u003eOpen ports without an accompanying proof-of-concept (POC) demonstrating a vulnerability\u003c/li\u003e\n\u003cli\u003eVulnerabilities only affecting users of outdated or unpatched browsers\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eProduct List\u003c/h2\u003e\n\n\u003cp\u003eThe following products are in-scope for Bounty Rewards. This list is subject to change at any time:\u003c/p\u003e\n\n\u003ch3\u003eClient Solutions\u003c/h3\u003e\n\n\u003ch4\u003eHardware Products\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eConsumer Platforms (i.e., Inspiron, Alienware, XPS)\u003c/li\u003e\n\u003cli\u003eCommercial Platforms  (i.e., Latitude, OptiPlex, Precision, Rugged, Latitude Education, Chrome, Dell Thin Client) \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eDell-branded client peripherals\u003c/h3\u003e\n\n\u003ch4\u003eSoftware Products\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eAlienware Command Center\u003c/li\u003e\n\u003cli\u003eAlienware OC Controls\u003c/li\u003e\n\u003cli\u003eAlienware Update\u003c/li\u003e\n\u003cli\u003eDell Command Configure\u003c/li\u003e\n\u003cli\u003eDell Command Integration Suite for System Center\u003c/li\u003e\n\u003cli\u003eDell Command Intel vPro Out of Band\u003c/li\u003e\n\u003cli\u003eDell Command Monitor\u003c/li\u003e\n\u003cli\u003eDell Command Powershell Provider\u003c/li\u003e\n\u003cli\u003eDell Command Repository Manager\u003c/li\u003e\n\u003cli\u003eDell Command Update\u003c/li\u003e\n\u003cli\u003eDell Core Services Cloud\u003c/li\u003e\n\u003cli\u003eDell Customer Connect\u003c/li\u003e\n\u003cli\u003eDell Hybrid Client\u003c/li\u003e\n\u003cli\u003eDell OS Recovery Tool\u003c/li\u003e\n\u003cli\u003eDell Optimizer\u003c/li\u003e\n\u003cli\u003eDell Performance Manager\u003c/li\u003e\n\u003cli\u003eDell Display and Peripheral Manager\u003c/li\u003e\n\u003cli\u003eDell Power Manager\u003c/li\u003e\n\u003cli\u003eDell Pro AI Studio\u003c/li\u003e\n\u003cli\u003eDell Remediation Platform \u003c/li\u003e\n\u003cli\u003eDell Rugged Control Center\u003c/li\u003e\n\u003cli\u003eDell SupportAssist OS Recovery\u003c/li\u003e\n\u003cli\u003eDell SupportAssist for Home PCs\u003c/li\u003e\n\u003cli\u003eDell SupportAssist for Business PCs\u003c/li\u003e\n\u003cli\u003eDell Telemetry Platform Service\u003c/li\u003e\n\u003cli\u003eDell Trusted Device\u003c/li\u003e\n\u003cli\u003eDell Update\u003c/li\u003e\n\u003cli\u003eDell Web Services\u003c/li\u003e\n\u003cli\u003eWyse Management Suite\u003c/li\u003e\n\u003cli\u003eWyse Proprietary OS (Modern ThinOS)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eInfrastructure - Servers, Storage and Networking\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eCommon Event Enabler (CEE)\u003c/li\u003e\n\u003cli\u003eData Protection Central\u003c/li\u003e\n\u003cli\u003eDell AppSync\u003c/li\u003e\n\u003cli\u003eDell BSAFE \u003c/li\u003e\n\u003cli\u003eDell Cloud Disaster Recovery\u003c/li\u003e\n\u003cli\u003eDell CloudLink\u003c/li\u003e\n\u003cli\u003eDell Container Storage Modules\u003c/li\u003e\n\u003cli\u003eDell Data Lakehouse\u003c/li\u003e\n\u003cli\u003eDell ECS\u003c/li\u003e\n\u003cli\u003eDell Enterprise Storage Analytics for vRealize Operations\u003c/li\u003e\n\u003cli\u003eDell Networking C Series Switch\u003c/li\u003e\n\u003cli\u003eDell Networking H-Series Edge Switch\u003c/li\u003e\n\u003cli\u003eDell Networking X-Series Smart Managed Switches\u003c/li\u003e\n\u003cli\u003eDell OpenManage Enterprise Modular\u003c/li\u003e\n\u003cli\u003eDell OpenManage Enterprise\u003c/li\u003e\n\u003cli\u003eDell OpenManage Network Integration\u003c/li\u003e\n\u003cli\u003eDell OpenManage Integration for ServiceNow\u003c/li\u003e\n\u003cli\u003eDell OpenManage Enterprise Power Manager Plugin\u003c/li\u003e\n\u003cli\u003eDell OpenManage Server Administrator\u003c/li\u003e\n\u003cli\u003eDell OpenManage Enterprise Services\u003c/li\u003e\n\u003cli\u003eDell OpenManage Connections - ServiceNow\u003c/li\u003e\n\u003cli\u003eDell OpenManage Integration with Microsoft Windows Admin Center\u003c/li\u003e\n\u003cli\u003eDell PowerEdge - 16th and 17th generation servers\u003c/li\u003e\n\u003cli\u003eDell PowerFlex \u003c/li\u003e\n\u003cli\u003eDell PowerMax \u003c/li\u003e\n\u003cli\u003eDell PowerProtect Cyber Recovery\u003c/li\u003e\n\u003cli\u003eDell PowerProtect Data Manager\u003c/li\u003e\n\u003cli\u003eDell PowerProtect DD Series Appliance\u003c/li\u003e\n\u003cli\u003eDell PowerProtect DP Series Appliance\u003c/li\u003e\n\u003cli\u003eDell PowerScale\u003c/li\u003e\n\u003cli\u003eDell PowerStore\u003c/li\u003e\n\u003cli\u003eDell PowerSwitch\u003c/li\u003e\n\u003cli\u003eDell Repository Manager (DRM)\u003c/li\u003e\n\u003cli\u003eDell SC Series Fibre Channel and iSCSI Drivers\u003c/li\u003e\n\u003cli\u003eDell SCOM SNMP Management Pack Suite\u003c/li\u003e\n\u003cli\u003eDell SD-WAN Edge\u003c/li\u003e\n\u003cli\u003eDell Secure Connect Gateway (SCG)\u003c/li\u003e\n\u003cli\u003eDell Server Update Utility (SUU)\u003c/li\u003e\n\u003cli\u003eDell Storage Manager\u003c/li\u003e\n\u003cli\u003eDell System Update (DSU)\u003c/li\u003e\n\u003cli\u003eDell Unity\u003c/li\u003e\n\u003cli\u003eDell Update Manger plugin (UMP)\u003c/li\u003e\n\u003cli\u003eDell Virtual Storage Integrator for VMware vSphere Client\u003c/li\u003e\n\u003cli\u003eDell VxRail HCI\u003c/li\u003e\n\u003cli\u003eEnterprise SONiC Distribution\u003c/li\u003e\n\u003cli\u003ePowerEdge M-Series Blade Switch\u003c/li\u003e\n\u003cli\u003eSmartFabric OS10\u003c/li\u003e\n\u003cli\u003eSmartFabric Storage Software\u003c/li\u003e\n\u003cli\u003eTransparent Snapshot Data Mover (TSDM)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eMobile Applications\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eCloudIQ\u003c/li\u003e\n\u003cli\u003eE-Lab Navigator\u003c/li\u003e\n\u003cli\u003eOpenManage Mobile\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eProgram Rules\u003c/h3\u003e\n\n\u003ch4\u003eLegal Terms:\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eBy participating in this Bug Bounty Program, you agree to be bound to the terms of this program brief (“Dell Terms \u0026amp; Conditions”).* These terms constitute the entire agreement between you and Dell, and are governed by Texas law. Any changes to these terms must be in writing.\u003c/li\u003e\n\u003cli\u003eThese terms constitute the entire agreement between you and Dell, and are governed by Texas law. Any changes to these terms must be in writing.\u003c/li\u003e\n\u003cli\u003eThe intent of this Bug Bounty Program is to encourage coordinated disclosure between you and Dell. Unless required by federal law or local law enforcement, Dell does not intend to pursue litigation against research and disclosure that meets the Dell Terms \u0026amp; Conditions.\u003c/li\u003e\n\u003cli\u003eIf legal action is initiated by a third party against you relative to this Bug Bounty Program and you are in full compliance with the Dell Terms \u0026amp; Conditions, Dell may at its sole discretion take reasonable steps to help make it known that your actions were conducted in compliance with this program.\u003c/li\u003e\n\u003cli\u003eDell will not publicly disclose the identity of any researcher without their consent, except where required by law.\u003c/li\u003e\n\u003cli\u003eDell reserves the right to change or modify the Dell Terms \u0026amp; Conditions at any time. Check for any updates to this program brief before creating a new submission.\u003c/li\u003e\n\u003cli\u003eBy participating in this Bug Bounty Program you waive any rights to the confidentiality of the submitted work and, further, you agree to grant Dell an irrevocable, worldwide, royalty-free, perpetual and transferable license to use the submitted research, disclosure and materials and you waive any claims against Dell based on Dell’s license or the rights granted.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eDisclosure:\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eThis program does not allow researchers to disclose the results of a submission.\u003c/li\u003e\n\u003cli\u003ePublic disclosures will make the researcher ineligible for future participation in this or other disclosure or bug bounty programs by Dell.\u003c/li\u003e\n\u003cli\u003eRewards will not be given for submissions which are publicly disclosed.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eRewards:\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eThis program does not offer rewards for out-of-scope targets, excluded submission types, or excluded products\u003c/li\u003e\n\u003cli\u003eDell will not negotiate in response to duress or threats (e.g., we will not negotiate the payout amount under threat of withholding the vulnerability or threat of releasing the vulnerability or any exposed data to the public).\u003c/li\u003e\n\u003cli\u003eIf multiple reports are received for the same issue the reward will be awarded to the earliest report containing enough information to reproduce. Dell will not offer rewards for previously known issues. Dell determines duplicates at its sole discretion and will not share details on other reports.\u003c/li\u003e\n\u003cli\u003eIdentical issues across different products and environments will be considered duplicates.\u003c/li\u003e\n\u003cli\u003eOnly researchers with valid submissions will be listed on the \u003ca href=\"https://bugcrowd.com/dell/hall-of-fame\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eDell Technologies Hall of Fame\u003c/a\u003e. Dell will not acknowledge a researcher on a Hall of Fame separate from Bugcrowd’s unless a CVE is assigned based on the report.  With the researcher’s permission Dell Security Advisories will acknowledge the submitter of the finding.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eTesting:\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eDell does not provide products for security testing. Any testing by the researcher should only be against Dell products which you have authorized access.\u003c/li\u003e\n\u003cli\u003eTesting must not violate any applicable laws or regulations or disrupt or compromise any data that is not your own. If you inadvertently cause a violation or disruption (such as accessing the data of other users, service configurations, or other confidential information) while testing, report the incident immediately to \u003ca href=\"mailto:secure@dell.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003esecure@dell.com\u003c/a\u003e. Any data accessed during your testing must not be used, disclosed, stored, or recorded in any way.\u003c/li\u003e\n\u003cli\u003eDo not exploit a vulnerability you discover beyond what is needed to obtain the proof of concept.\u003c/li\u003e\n\u003cli\u003eAutomated vulnerability scanning tools are strictly prohibited as part of this and any other Dell program.\u003c/li\u003e\n\u003cli\u003eDenial of Service (DoS) and Distributed Denial of Service (DDoS) based attacks are strictly prohibited as part of this and any other Dell program.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eEligibility\u003c/h4\u003e\n\n\u003cp\u003eYou are not eligible to participate in program if you are: \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eA current employee of Dell or a Dell subsidiary, or an immediate family (parent, sibling, spouse, or child) or household member of such an employee. \u003c/li\u003e\n\u003cli\u003eA contingent staff member, contractor or vendor employee currently working with Dell. \u003c/li\u003e\n\u003cli\u003eA former employee or contractor of Dell who was involved in the development or testing of the Dell web property or application listed in the target section.\u003c/li\u003e\n\u003cli\u003eLocated in a non-United States export/trade sanction country.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eIf you find a vulnerability that is not in the scope of this Bug Bounty Program, send the report to \u003ca href=\"mailto:secure@dell.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003esecure@dell.com\u003c/a\u003e.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"1436e298-d796-4698-b516-34f9a6f8c94d","name":"█████████████████████████████████","targets":[{"id":"9d79f990-ceb3-4ed4-b0c7-29d13d0202f1","uri":null,"name":"█████████████████████████████████████████████████","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"3ee62028-c26f-4c6a-87a7-59058cb6aaaf","sortOrder":0},"sortOrder":0,"tags":[{"id":"6825f068-7447-450e-9134-158ae26e18d4","name":"Computer Hardware","targetId":"9d79f990-ceb3-4ed4-b0c7-29d13d0202f1"},{"id":"ee6e7cc3-455d-4d97-b43e-5b8de420d096","name":"Hardware Testing","targetId":"9d79f990-ceb3-4ed4-b0c7-29d13d0202f1"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"26a8534b-59a2-429b-a5d2-40ba4d82878d","p1MaxCents":500000,"p1MinCents":500000,"p2MaxCents":300000,"p2MinCents":300000,"p3MaxCents":150000,"p3MinCents":150000,"p4MaxCents":20000,"p4MinCents":20000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"███████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████","rewardRangeData":{"1":{"min":5000,"max":5000},"2":{"min":3000,"max":3000},"3":{"min":1500,"max":1500},"4":{"min":200,"max":200},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"9711d4c8-5200-4ce1-a146-c82e2dd9f90b","name":"███████████████████████████","targets":[{"id":"2382c853-1fd2-4f0c-8c43-be2d76f60848","uri":null,"name":"█████████████████████████████████████████████████████","category":"hardware","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"6688c2ac-cd81-4e04-b26a-ddb5f758a47a","sortOrder":0},"sortOrder":0,"tags":[{"id":"6825f068-7447-450e-9134-158ae26e18d4","name":"Computer Hardware","targetId":"2382c853-1fd2-4f0c-8c43-be2d76f60848"},{"id":"ee6e7cc3-455d-4d97-b43e-5b8de420d096","name":"Hardware Testing","targetId":"2382c853-1fd2-4f0c-8c43-be2d76f60848"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":"██████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████","rewardRangeData":{},"recentChangeFlags":null},{"id":"e6beac08-3854-41af-84cd-241664ecf2a7","name":"█████████████████████████████████████████████","targets":[{"id":"1d276c9d-e1e9-4c5a-bc9e-736bdfde6b27","uri":null,"name":"████████████","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"ffe04e6a-fd69-4aa6-8341-5ca7cd1173b3","sortOrder":0},"sortOrder":0,"tags":[{"id":"32a00682-97f0-4d01-852d-f06359bdc440","name":"Bootstrap","targetId":"1d276c9d-e1e9-4c5a-bc9e-736bdfde6b27"},{"id":"6481be19-8d64-4bb2-8426-2f1f7afe32e6","name":"Modernizr","targetId":"1d276c9d-e1e9-4c5a-bc9e-736bdfde6b27"},{"id":"68da3fae-5355-463e-8442-9a5016b1bda0","name":"ASP.NET","targetId":"1d276c9d-e1e9-4c5a-bc9e-736bdfde6b27"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"1d276c9d-e1e9-4c5a-bc9e-736bdfde6b27"},{"id":"b6333057-ce1f-4205-bcb6-ce56be83543b","name":"Microsoft IIS","targetId":"1d276c9d-e1e9-4c5a-bc9e-736bdfde6b27"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"1d276c9d-e1e9-4c5a-bc9e-736bdfde6b27"}],"recentChangeFlags":null},{"id":"b70c6883-670b-400b-9433-a7b2ee45e09c","uri":null,"name":"████████████████████████","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"6efdb547-7ffc-47f2-ae88-0b23a350549d","sortOrder":0},"sortOrder":0,"tags":[{"id":"187a0132-af2c-45e1-b4af-77ac6117b9dc","name":"Adobe Experience Manager","targetId":"b70c6883-670b-400b-9433-a7b2ee45e09c"},{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"b70c6883-670b-400b-9433-a7b2ee45e09c"},{"id":"32a00682-97f0-4d01-852d-f06359bdc440","name":"Bootstrap","targetId":"b70c6883-670b-400b-9433-a7b2ee45e09c"},{"id":"4077ab03-37ce-4c7d-8634-ea59ba5ef456","name":"Varnish","targetId":"b70c6883-670b-400b-9433-a7b2ee45e09c"},{"id":"6481be19-8d64-4bb2-8426-2f1f7afe32e6","name":"Modernizr","targetId":"b70c6883-670b-400b-9433-a7b2ee45e09c"},{"id":"6f2f82a5-9ef3-4bc5-9d86-6634e03133e1","name":"Recon","targetId":"b70c6883-670b-400b-9433-a7b2ee45e09c"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"b70c6883-670b-400b-9433-a7b2ee45e09c"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"b70c6883-670b-400b-9433-a7b2ee45e09c"},{"id":"e591e8bc-d7f4-49ad-952f-98dee6c92653","name":"DNS","targetId":"b70c6883-670b-400b-9433-a7b2ee45e09c"}],"recentChangeFlags":null},{"id":"3e1ffff0-2c9d-44c7-9c92-fe8868c8d305","uri":null,"name":"████████████████████████████████","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"c353454a-1d47-4724-b19d-9075c35724bb","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"fe64a7c2-1667-4a19-982c-03f119e43992","uri":null,"name":"████████████████","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"56bcc93b-fa13-48ba-a262-9d117a735920","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"305e80d2-eacd-41db-a160-0c1989ee7de2","uri":null,"name":"█████████████████████","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"4c2e7c55-ceb6-4d69-a718-8e167bc62b39","sortOrder":4},"sortOrder":4,"tags":null,"recentChangeFlags":null},{"id":"bb1bc97d-66ef-4e60-b143-623ab846626d","uri":null,"name":"███████████████████","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"fe4c7825-e331-466e-b5b5-ee0e0831c440","sortOrder":5},"sortOrder":5,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":2,"description":null,"rewardRange":null,"descriptionHtml":"████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"f50364ea-b2d0-4915-bf3e-7c26e172fca1","code":"dell-product","state":"in_progress_paused","endsAt":null,"bountyId":"7706ed90-8363-4f5a-9e94-bf3e06c46d45","startsAt":"2021-10-19T19:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Hardware","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/89c6/0c64/4d2a0dff/3eb9e961dbf9c0e5346bea3ec89e9596_dell_technologies_logo.jpeg","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":"Dear Researchers,\n\nWe want to sincerely thank you for your continued engagement, high-quality submissions, and support of our Product bug bounty program. Your contributions play an important role in helping us strengthen our product security posture.\n\n\nWe’re writing to inform you that we will be temporarily pausing our Product bug bounty program, effective June 24, 2026.\n\n\nWhat this means:\n\n\nWe will continue to review and triage all valid submissions received prior to the pause date.\nAny eligible reports submitted before the pause will be evaluated in accordance with our program policy.\n\nDuring this pause, we are not accepting new submissions through the bug bounty program.\n\nWe remain committed to responsible disclosure and welcome researchers to report potential security vulnerabilities to us directly. Please refer to our Vulnerability Response Policy for details on how to submit reports and how they will be handled during this period.\n\n\nWe deeply value the partnership we’ve built with the research community and appreciate your understanding. We will share updates as they become available regarding the program","lastTransitionAt":"2026-06-29T15:49:26.867Z","cancellationReason":null,"statusLabel":"In progress paused","routesPaths":{"brief":"/engagements/dell-product","changelogs":"/engagements/dell-product/changelog","submissions":null,"announcements":"/engagements/dell-product/announcements","hallOfFame":"/engagements/dell-product/hall_of_fames","crowdstream":null},"announcementsCount":4,"knownIssuesEnabled":false,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":null,"methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=dell-product\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/dell-product/engagement_subscribers","engagementChangelogsUrl":"/engagements/dell-product/changelog","publishedAt":"2026-06-29T15:49:26.898Z","engagementChangelogUrl":"/engagements/dell-product/changelog/bafce899-ed68-4708-b2dc-1c8485d69024","createUserFeedbacksUrl":"/engagements/dell-product/feedbacks","engagementCrowdstreamUrl":null,"acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}