Report an exploited vulnerability
Have you discovered an actively exploited software vulnerability in Mascot Server, Mascot Distiller or Mascot Daemon?
Have you suffered a severe cybersecurity incident involving Mascot Server, Mascot Distiller or Mascot Daemon?
Please report it to us immediately by email at: exploited_vulnerability@matrixscience.com.
To help us triage your report, include at minimum:
- Product name and exact version
- Operating system and exact version
- Web server name and exact version (Mascot Server only)
- Configuration files or switches relevant to triggering the vulnerability
- If relevant, any locally applied modifications to the product, e.g. custom reporting scripts
- Input data required for triggering the vulnerability
- Exact steps to reproduce the exploit; include screenshots, logs or network traces where appropriate
- Description of the effects of the exploit, e.g. does it allow remote code execution, denial of service, breach of access restrictions or something else
- Whether you suspect the exploit is being used by unlawful or malicious actors
An actively exploited vulnerability is “a vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without permission of the system owner”, as defined in the EU Cyber Resilience Act (CRA) article 3.
A severe incident is “an incident that negatively affects or is capable of negatively affecting the ability of a product with digital elements to protect the availability, authenticity, integrity or confidentiality of data or functions”, as defined in the EU Cyber Resilience Act (CRA) article 3.
How your report is processed
IMPORTANT: Matrix Science Ltd is a microenterprise as per EU definitions, and we do not have the resources to run a 24/7 incident response team. We will endeavour to investigate all exploited vulnerability reports within 2 working days, excluding UK public holidays. If you require 24/7 cybersecurity incident response from your proteomics software supplier, you should stop using Mascot Server, Mascot Daemon and Mascot Distiller and seek an alternative software solution.
Matrix Science Ltd is based in the United Kingdom. We are obligated to report certain types of cybersecurity incidents to European Union (EU) authorities as our products are sold within the EU.
When you send us a report by email, we will investigate it within 2 working days, excluding UK public holidays. If you are reporting an actively exploited vulnerability or a severe incident, and we are able to reproduce it, we will report it to the European Union Agency for Cybersecurity (ENISA) and the relevant national Computer Security Incident Response Team (CSIRT). We will file the first alert within 24h of confirming your findings, as required by the CRA. We will inform you as soon as possible after the report has been filed. If we are unable to reproduce your findings, we will contact you by email for more information.
Next, we will identify any corrective or mitigating measures users can take. We will file the report to ENISA within 72h of the initial alert, including the corrective or mitigating measures.
For an actively exploited vulnerability, we will either distribute the mitigation instructions to affected users as soon as possible, or prepare a security update to the relevant product version. In either case, we will file the final report with ENISA and the relevant national CSIRT within 14 days of distributing the mitigating measure or security update.
For a confirmed severe incident, we will compile a detailed description of the incident, severity and impact, the likely root cause and applied mitigation measures. We will file the final report with ENISA and the relevation national CSIRT within 1 month, as required by the CRA.
If your report describes a vulnerability that is theoretical, not exploitable or not actively exploited, or if the report looks like it has been generated by a large-language model (LLM) and not verified by a human, we will log it as a bug report and implement a suitable mitigation or fix in the normal course of software development.
Co-ordinated disclosure
After emailing your report, please do not disclose any exploits in public until we have had a reasonable opportunity to investigate, remediate and notify affected customers.
Privacy and data handling
We will not share your name or contact details with third parties without your permission, unless required by law.