{"id":"8309ce5f-7aef-4b6d-ae29-7caff006d774","engagementId":"1753c3bf-25ec-4ee6-a3a1-f64e96d29805","data":{"brief":{"id":"d47b19c6-62e7-4340-b71c-710755e6bb69","name":"Trimble Vulnerability Disclosure Program","tagline":"Tomorrow’s Designs, Today","description":"\u003cp\u003eAt Trimble Inc., we are committed to ensuring the security and privacy of our customers and their data. We value the role that independent security researchers play in the ecosystem. Our Vulnerability Disclosure Program (VDP) is designed to provide a clear and safe channel for reporting potential security vulnerabilities.\u003c/p\u003e\n\n\u003cp\u003eWe encourage you to report any potential security issues you discover in accordance with the program guidelines. Your efforts help us stay vigilant and proactive. Good luck and happy hunting! \u003c/p\u003e\n\n\u003ch2\u003eRatings\u003c/h2\u003e\n\n\u003cp\u003eFor the initial rating of findings, this engagement will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, in some cases a vulnerability rating will be modified due to its likelihood or impact.\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003ch2\u003eVulnerability Disclosure Program Guidelines\u003c/h2\u003e\n\n\u003cp\u003eThank you for your interest in participating in Trimble’s Vulnerability Disclosure Program (VDP). Participation in the program is subject to and governed by these Guidelines. Research leading to a disclosed vulnerability that complies with these guidelines will be considered Trimble-sponsored research and will fall under our Safe Harbor policy. If these guidelines conflict with any other applicable terms, these guidelines will control with respect to that conflict.\u003c/p\u003e\n\n\u003cp\u003eTrimble reserves the right to modify or cancel the VDP at any time without notice. All participants and submissions are strictly voluntary. This program is void where prohibited by law.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eParticipant Guidelines\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eWhen conducting your research you must follow these guidelines:\u003c/em\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003ePurpose:\u003c/strong\u003e Research must be lawful, helpful to the overall security of the Internet, and conducted in good faith.  You must comply with all applicable laws, rules and regulations.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eAccount Usage:\u003c/strong\u003e You must create your own accounts for testing purposes where applicable. You must only interact with test accounts you own or with the explicit permission of the account holder.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eData Privacy:\u003c/strong\u003e Do not violate the privacy of others. If your testing provides unintended access to data, you must limit the amount of data accessed to the minimum required to demonstrate a Proof of Concept.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eHandling Sensitive Data:\u003c/strong\u003e If you encounter user data such as Personally Identifiable Information (PII), Personal Healthcare Information (PHI), credit card data, or proprietary information, you must cease testing immediately and submit a report.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eProhibited Actions:\u003c/strong\u003e The following actions are strictly prohibited:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eDisrupting our or any third party systems, destroying data, or harming the user experience.\u003c/li\u003e\n\u003cli\u003eEngaging in any form of \"Social Engineering\", phishing, or similar attacks.\u003c/li\u003e\n\u003cli\u003eConducting availability or volumetric testing, such as DoS, DDoS, rate limiting bypass attempts, or email bombing.\u003c/li\u003e\n\u003cli\u003eUsing any leaked credentials during testing.\u003c/li\u003e\n\u003cli\u003eEngaging in extortion or any other illegal, unethical, or immoral behavior.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eReporting Guidelines\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eTo ensure your submission is processed efficiently, you must follow these guidelines:\u003c/em\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eOfficial Channel:\u003c/strong\u003e All security issues and reports must be submitted through the submission form available through Trimble’s page on the Bugcrowd-hosted Vulnerability Disclosure Program.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eReport Requirements:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eReports must include a clear explanation of the vulnerability, its security impact, and detailed steps to reproduce it. The more details you provide, the easier it will be to triage and fix the issue.\u003c/li\u003e\n\u003cli\u003eWe do not accept reports containing low-effort or AI-generated content. Reports that we determine lack meaningful human input will be rejected.\u003c/li\u003e\n\u003cli\u003eYour submission must demonstrate original analysis and a clear understanding of the issue.\u003c/li\u003e\n\u003cli\u003eDo not submit more than one vulnerability per report. If demonstrating impact requires chaining multiple vulnerabilities, they can be included in the same report as long as the connection is clearly explained.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003ePrompt Disclosure and Communication Required\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eReport any vulnerability you discover promptly.\u003c/li\u003e\n\u003cli\u003eUse only this official channel to discuss vulnerability information with us.\u003c/li\u003e\n\u003cli\u003eDo not discuss or disclose any vulnerabilities, even resolved ones, outside of the program without Trimble’s express consent to do so.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOur Commitment to You\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eWhen you participate in our VDP according to this policy, you can expect us to:\u003c/em\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eRespond to your report promptly and collaborate with you to understand and validate it.\u003c/li\u003e\n\u003cli\u003eStrive to keep you informed about the progress of your report.\u003c/li\u003e\n\u003cli\u003eWork to remediate validated vulnerabilities in a timely manner, within our operational constraints.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eExcluded Submissions\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eP5 vulnerabilities for all targets.\u003c/li\u003e\n\u003cli\u003eP4 \u0026amp; P5 vulnerabilities for desktop applications.\u003c/li\u003e\n\u003cli\u003eXSS submissions for web applications except for Stored XSS.\u003c/li\u003e\n\u003cli\u003eSubmissions related to leaked credentials may be reviewed on a case-by-case basis.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003eTrimble will not initiate civil or criminal legal action against any researcher for accidental, good-faith violations of these Guidelines or applicable anti-hacking laws, such as the Computer Fraud and Abuse Act (CFAA) and the Digital Millennium Copyright Act (DMCA), provided that the researcher's activities are:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eConducted in accordance with and limited to the scope and guidelines of the Program Brief;\u003c/li\u003e\n\u003cli\u003eConsistent with these Guidelines; and\u003c/li\u003e\n\u003cli\u003eCarried out in a manner that does not harm Trimble or our customers.\nThis Safe Harbor is a statement of our current practice and does not confer any legal rights upon you. It is void if you violate these Guidelines. Trimble cannot and does not authorize security research on behalf of other entities and cannot offer any protection from third-party claims.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"2d7337a9-c7dc-407a-a591-fff0c9e69fce","name":"In Scope","targets":[{"id":"6211e67b-668e-48fc-b963-bcf2cbad889c","uri":"","name":"All Trimble Owned Endpoints","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"228128ba-de52-4965-882e-8297df67782c","sortOrder":0},"sortOrder":0,"tags":[{"id":"057eb8bf-b949-4f16-95f2-5bd83851a78d","name":"Network Testing","targetId":"6211e67b-668e-48fc-b963-bcf2cbad889c"},{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"6211e67b-668e-48fc-b963-bcf2cbad889c"},{"id":"02370343-bf13-4661-a7a2-caa1c1076ad1","name":"Computer Software","targetId":"6211e67b-668e-48fc-b963-bcf2cbad889c"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"1753c3bf-25ec-4ee6-a3a1-f64e96d29805","code":"trimble-vdp-pro","state":"in_progress","endsAt":null,"bountyId":"d80cd500-1bb8-49e9-840e-542e1bceed5c","startsAt":"2025-10-21T18:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/engagement_brief_logos/engagement_brief/logo/d47b19c6-62e7-4340-b71c-710755e6bb69/9b5e21fd-2d56-46f3-95a4-bc81c84f7778.png","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-10-21T18:00:00.223Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/trimble-vdp-pro","changelogs":"/engagements/trimble-vdp-pro/changelog","submissions":null,"announcements":"/engagements/trimble-vdp-pro/announcements","hallOfFame":"/engagements/trimble-vdp-pro/hall_of_fames","crowdstream":null},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/trimble-vdp-pro/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=trimble-vdp-pro\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/trimble-vdp-pro/engagement_subscribers","engagementChangelogsUrl":"/engagements/trimble-vdp-pro/changelog","publishedAt":"2025-12-29T02:49:02.885Z","engagementChangelogUrl":"/engagements/trimble-vdp-pro/changelog/8309ce5f-7aef-4b6d-ae29-7caff006d774","createUserFeedbacksUrl":"/engagements/trimble-vdp-pro/feedbacks","engagementCrowdstreamUrl":null,"acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}