{"id":"798c8b8b-e02c-4abd-91a1-f8bb53aca527","engagementId":"6e3d7e5f-5e4e-4123-8ca2-81892546f5fa","data":{"brief":{"id":"0d7418e3-2b5b-41eb-9e6b-afdab5e7e98f","name":"Lumen VDP","tagline":"The Lumen Vulnerability Disclosure Program","description":"\u003cp\u003e\u003cstrong\u003eVulnerability Disclosure Policy\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eLumen cares deeply about maintaining the trust and confidence that parties place in us. Accordingly, a top priority at Lumen is the security of our systems and the services they may support. Lumen applies a rigorous process to continually evaluate and improve our vulnerability response practices, including encouraging the disclosure of identified vulnerabilities under this Vulnerability Disclosure Policy. If you are a security researcher and have discovered a security vulnerability in one of our systems, we encourage you to disclose it to us in a responsible manner and in accordance with this Policy. We will not engage with security researchers who do not follow the terms of this Policy. Lumen will validate and remediate vulnerabilities in accordance with our commitment to security and privacy. Lumen will not take legal action against researchers who discover and report security vulnerabilities to us in good faith and in accordance with this Policy.\u003c/p\u003e\n\n\u003cp\u003eThis Policy applies to Lumen and its affiliate companies, including CenturyLink and Quantum Fiber.\u003c/p\u003e\n\n\u003cp\u003eWe encourage security researchers to share the details of any suspected vulnerabilities with the Lumen Information Security Team through this program. A vulnerability is an error, flaw, mistake, failure, or fault in a computer program found within Lumen’s publicly accessible online environment that affects the security of a device, system, network, or data.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003cp\u003e\u003cstrong\u003eWe ask the following of you when conducting vulnerability research and submitting vulnerabilities to Lumen:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eReport identified vulnerabilities to us immediately, as timely identification of security vulnerabilities is critical to mitigating potential risks;\u003c/li\u003e\n\u003cli\u003eCooperate with us while we review the submission to determine if the finding is valid and has not been previously reported;\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eInclude as much of the below information as possible to help us better understand the nature and scope of the reported issue:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eDetails necessary to identify the impacted system\u003c/li\u003e\n\u003cli\u003eType and/or class of vulnerability\u003c/li\u003e\n\u003cli\u003eStep-by-step instructions to reproduce the vulnerability\u003c/li\u003e\n\u003cli\u003eProof-of-concept or exploit code\u003c/li\u003e\n\u003cli\u003ePotential impact of the vulnerability\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eYour IP address when the vulnerability was detected. We will keep this data private and only use it to review logs related to your testing activity.\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003eRefrain from disclosing the identified vulnerability to anyone else for a reasonable period of time so that we may conduct validation and implement associated remedies for the vulnerability\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003cp\u003e\u003cstrong\u003eDo not engage in any of the following activities:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAccessing, downloading, or modifying data residing in any system or account that does not belong to you\u003c/li\u003e\n\u003cli\u003eExecuting or attempting to execute any “Denial of Service” attack\u003c/li\u003e\n\u003cli\u003eExecuting or attempting to execute any social engineering attacks\u003c/li\u003e\n\u003cli\u003ePosting, transmitting, uploading, linking to, sending, or storing any malicious software\u003c/li\u003e\n\u003cli\u003eTesting in a manner that would result in the sending unsolicited or unauthorized junk mail, spam, pyramid schemes, or other forms of unsolicited messages\u003c/li\u003e\n\u003cli\u003eTesting in a manner that would damage or degrade the operation of any Lumen systems\u003c/li\u003e\n\u003cli\u003eTesting third-party applications, websites, or services that integrate with or link to Lumen systems\u003c/li\u003e\n\u003cli\u003eTesting that may violate any applicable law or impact the security or integrity of any personal or confidential information\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eThis Policy and the Vulnerability Disclosure Program administered by Lumen is subject to change or cancellation at any time without notice. This Policy is for informational purposes only and it does not create any binding obligation on Lumen or any legal relationship between Lumen and anyone who submits a vulnerability.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003cp\u003e\u003cstrong\u003eRatings/Rewards\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. To qualify for a P1 or P2 classification, a major product or environment must be impacted. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal and make a case for a higher priority.\u003c/p\u003e","industryTagId":"46b8dcc8-bbd9-4a60-80ab-ab088c2bc3e4","targetsOverview":"\u003cp\u003e\u003cem\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Lumen not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you believe you've identified a vulnerability on a system outside the scope, please reach out to \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support\u003c/a\u003e before submitting.\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eTraffic Identification and IP Address Requirement\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWhen accessing our targets, the following request header is required to identify your traffic:\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eIdentifier\u003c/th\u003e\n\u003cth\u003eHeader\u003c/th\u003e\n\u003cth\u003eExample\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eUsername\u003c/td\u003e\n\u003ctd\u003eX-Bug-Bounty: Bugcrowd-\u0026lt;Username\u0026gt;\u003c/td\u003e\n\u003ctd\u003eX-Bug-Bounty: Bugcrowd-proresearcher\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003cp\u003e*Also, when submitting a finding, please provide your IP address that was used when the vulnerability was detected. We will keep this data private and only use it to review logs related to your testing activity.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003e\u003cem\u003eUnidentified traffic may result in reward delays.\u003c/em\u003e\u003c/strong\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ecreate a ticket with Bugcrowd Support\u003c/a\u003e for clarification before proceeding.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":false,"additionalInformation":"\u003cp\u003eLumen utilizes multiple sources of threat intelligence and vulnerability reporting in addition to Bugcrowd. If a finding has already been identified and reported through another source, a subsequent Bugcrowd submission for the same issue may be marked as a duplicate.\u003c/p\u003e"},"scope":[{"id":"147b6fab-bb08-4703-863e-6ef82e06ccde","name":"In Scope","targets":[{"id":"6bc6f12e-a44a-4552-a8bd-6870d5604347","uri":"","name":"lumen.com","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"d4456adc-5499-479c-a938-4d22c7925019","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"9a96f40c-bad0-4480-9bcf-a53d939f8b66","uri":"","name":"centurylink.com","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"f8e41d3f-3a24-4c8c-bc30-61b233bb5eef","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"0db082d9-1d0b-4001-a308-54719e07684a","uri":"","name":"level3.com","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"e6d7f34a-6a9c-41ec-9c82-5e5d2b54bb7e","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"69cabe6e-07cb-4e01-b3a9-180dd1d78105","uri":"","name":"ctl.io","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"37e24ffc-b340-4a13-ac69-010533999e7d","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"60327f4d-1362-4866-afc0-d5eb1d6199c8","uri":"","name":"savvis.com","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"956fe728-e1bb-47ca-a0fb-ebadcf800af7","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"103433b3-83a8-4f55-b372-3541289bffcb","uri":"","name":"*.lumen.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"1468d488-6fe4-469d-851f-ff0cfc08c5ab","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eLumen is an ISP. Lumen relevant Domains ending in the TLD .net are customer subnets and vulnerabilities discovered in those domains exist on Lumen customer systems. Lumen customers, their networks and systems, and assets divested to third parties are explicitly not included in the Lumen VDP.\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null},{"id":"efa6249c-08f0-4eca-bf75-b1fe998242dc","name":"Out of Scope","targets":[{"id":"0a613994-fc48-463c-9fe2-4db0cfa6a89a","uri":"","name":"LATAM.lumen.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"30b3fb0f-47f5-4bca-aebc-7a20185b142b","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"fe5ad44a-11f6-4bd4-a2e6-789d45ac1849","uri":"","name":"lumenb1.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"38ffdaf0-52bf-4df2-a390-d064485ebe6c","sortOrder":1},"sortOrder":1,"tags":null,"recentChangeFlags":null},{"id":"58d372b0-9db3-4d19-b6a0-678dfb1af7f1","uri":"","name":"rtn04.lumen.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"d1de202c-42de-43f4-abb8-7d2fda34fd6f","sortOrder":2},"sortOrder":2,"tags":null,"recentChangeFlags":null},{"id":"d78f8eea-e5db-4d4d-bed4-3a9c21c1cf2a","uri":"","name":"*.lumen.net","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"1ad932b4-e4ff-46e4-88ad-521819a65b6b","sortOrder":3},"sortOrder":3,"tags":null,"recentChangeFlags":null},{"id":"bd16e949-e150-42df-97a3-cf9c137b68df","uri":null,"name":"ease*.lumen.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"0e6adc73-57ff-4868-9416-e6ad196ecf90","sortOrder":4},"sortOrder":4,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"6e3d7e5f-5e4e-4123-8ca2-81892546f5fa","code":"lumenvdp","state":"in_progress","endsAt":null,"bountyId":"a9597fa9-545a-45ae-ab86-97373087ec69","startsAt":"2022-03-31T00:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Technology","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/2654/cf7d/c83925f9/bd6fa119b1fe7e360b6402fedc8e5997_Lumen.jpeg","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":false,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2022-03-31T00:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/lumenvdp","changelogs":"/engagements/lumenvdp/changelog","submissions":null,"announcements":"/engagements/lumenvdp/announcements","hallOfFame":"/engagements/lumenvdp/hall_of_fames","crowdstream":null},"announcementsCount":3,"knownIssuesEnabled":false,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/lumenvdp/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=lumenvdp\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/lumenvdp/engagement_subscribers","engagementChangelogsUrl":"/engagements/lumenvdp/changelog","publishedAt":"2026-09-10T13:58:44.933Z","engagementChangelogUrl":"/engagements/lumenvdp/changelog/798c8b8b-e02c-4abd-91a1-f8bb53aca527","createUserFeedbacksUrl":"/engagements/lumenvdp/feedbacks","engagementCrowdstreamUrl":null,"acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}