SHENZHEN SINEXCEL ELECTRIC CO. LTD(以下、「当社」といいます。)は、お客様からの信頼を第一と考え、お客様個人に関わる情報を正確、かつ、機密に取り扱うことは、当社等にとって重要な責務であると考えております。そのために、個人情報の取り扱い方法について、 全社への徹底を実践してまいります。その内容は以下の通りです。
1、個人情報の取得および利用
当社が取得する個人情報は、原則としてお客様の意思によりご提供(登録)いただいた情報であるものとします。個人情報の取得は、お客様に明示した目的の達成に必要な限度においてこれを行います。なお、当社への個人情報のご提供(登録)を希望されない場合は、お客様自身のご判断により、提供を拒否することができます。この場合、当社において、個人情報が必要不可欠なサービスをご利用になれない場合があります。
また、当社が個人情報を収集・利用する目的は、以下のとおりです。
・ お客様へお知らせや連絡をするためにメールアドレスを利用したり、お客様へ資料を送付したり必要に応じて連絡したりするため、氏名や住所などの連絡先情報を利用する目的
・ お客様からのお問い合わせに対応するために、お問い合わせ内容など当社がお客様に対してサービスを提供するにあたって必要となる情報や、お客様の連絡先情報などを利用する目的
・ 上記の利用目的に付随する目的
2、利用目的の変更
当社は,利用目的が変更前と関連性を有すると合理的に認められる場合に限り,個人情報の利用目的を変更するものとします。
利用目的の変更を行った場合には,変更後の目的について,当社所定の方法により,ユーザーに通知し,または本ウェブサイト上に公表するものとします。
3、個人情報の第三者提供
当社は個人情報を第三者に販売することはありませんし、今後も販売しません。
当社は、(I) 書面によるお客様の事前同意がある場合、(II) 適用法令に準拠する場合や当局から要求された場合、(III) 本サービスを提供するのに必要な場合、(IV) 行政続きや司法手続き上の権利を守るため、または弊社の事業やその一部が他の第三者に譲渡される場合など、弊社の正当な利益保護を目的とする場合を除き、お客様の個人情報を開示することはありません。
お客様の個人情報へのアクセスは知る必要がある場合のみに制限し、従業員には個人情報の機密性を尊重し、ポリシーに従ってお客様の情報を保護することを求めています。
4、個人情報の訂正および削除
お客様は、当社が保有する自己の個人情報が誤った情報である場合には、当社が定める手続きにより、当社へ対して個人情報の訂正または削除を請求することができます。
当社は、お客様から前項の請求を受けてその請求に応じる必要があると判断した場合には、遅滞なく、当該個人情報の訂正または削除を行い、これをお客様に通知します。
5、個人情報の利用停止等
当社は、ご本人から個人情報が利用目的の範囲を超えて取り扱われているという理由、または不正な手段により取得されたものであるという理由により、その利用の停止または消去(以下、「利用停止等」といいます)を求められた場合には、遅滞なく必要な調査を行い、その結果に基づき個人情報の利用停止等を行い、その旨ご本人に通知します。
ただし、個人情報の利用停止等に多額の費用を有する場合その他利用停止等を行うことが困難な場合であって、ご本人の権利利益を保護するために必要なこれに代わるべき措置をとることができる場合は、この代替策を講じます。
6、クッキーの使用について
当社は、サービスの品質向上とお客様へのよりよいサービスの提供を目的として、当社のCookie(クッキー)をお客様がお使いのブラウザ(コンピュータ)に送信し、お客様が使用しているコンピュータに保存された当社のCookie情報を参照することがあります。
当社は、お客様のコンピュータに保存された当社のCookie情報を参照することにより、お客様がご利用になられた当社のサービス、当社の管理するWebサイト内でのお客様の行動履歴などの情報を収集することができます。
ただし、これらの情報はお客様個人を特定することのできる情報ではございません。当社のCookieの送受信を希望されない場合は、お客様がお使いのブラウザの設定を変更していただくことによって、当社のCookieの送受信を拒否し、もしくは当社のCookieを削除することができます。
7、本プライバシーポリシーの変更
当社は、本プライバシーポリシーをいつでも変更することができます。変更後の内容は、効力発生日を定めた上で、本Webサイトに掲載する方法により周知します。効力発生日またはその後において本Webサイトまたは関連サービスを継続して利用しているお客様は、変更後のプライバシーポリシーの内容に同意したものとみなします。
8、お問い合わせ窓口
当ポリシーに関するお問い合わせは、sales@sinexcel.comまでお願いいたします。
Security Vulnerability Classification and Countermeasures
セキュリティ脆弱性の分類と対策
Shenzhen Sinexcel Electric Co., Ltd (hereinafter referred to as "We" or "Sinexcel"), as a manufacturer of the products, attaches great importance to the security of its own products and business, and recognizes the importance of privacy and data security. The handling of each security vulnerability and the improvement of business security cannot be separated from the joint cooperation of all parties. If you discover or believe that you have discovered a potential security vulnerability in your use of our products, we encourage you to disclose your discovery to us as soon as possible in accordance with this Vulnerability Disclosure Policy. We promise that we have dedicated personnel to follow up, analyze and deal with the problems reported by each reporter, and will reply in time.
深セン市盛弘電気株式会社(以下「当社」または「Sinexcel」)は、製品メーカーとして、自社製品およびビジネスのセキュリティを非常に重視し、プライバシーとデータセキュリティの重要性を認識しています。個々のセキュリティ脆弱性の処理とビジネスセキュリティの向上は、すべての関係者の共同協力なしには実現できません。当社の製品を使用する際に潜在的なセキュリティ脆弱性を発見した、または発見したと思われる場合は、本脆弱性開示ポリシーに従って、できるだけ早く当社に開示することをお勧めします。当社は、各報告者によって報告された問題を追跡、分析、処理するための専任担当者を配置し、タイムリーに返答することをお約束します。
At Sinexcel, we prioritize the security experience of each user. If you encounter any potential security vulnerabilities or issues while using our products, we encourage you to report them to us immediately. Your active participation is a crucial element in helping us enhance product security.
Sinexcelでは、各ユーザーのセキュリティ体験を最優先しています。当社製品の使用中に潜在的なセキュリティ脆弱性や問題に遭遇した場合は、直ちに当社に報告することをお勧めします。お客様の積極的なご参加は、当社が製品のセキュリティを向上させる上で重要な要素となります。
Reporting Steps: / 報告手順:
Identify the issue: Please provide a detailed description of the security problem or vulnerability you have identified, including the product model where the issue occurred and specific circumstances.
問題の特定:発見したセキュリティ問題または脆弱性の詳細な説明(問題が発生した製品モデルや具体的な状況を含む)を提供してください。
Collect information: If possible, please provide steps to reproduce the issue, the scope of its impact, and any relevant screenshots or logs.
情報の収集:可能な場合、問題を再現する手順、その影響範囲、および関連するスクリーンショットやログを提供してください。
Submit the report: Please send an email to solutions@sinexcel.us to report the issue to our product security team.
レポートの提出:当社の製品セキュリティチームに問題を報告するには、solutions@sinexcel.us 宛てに電子メールを送信してください。
Step 1: The reporter needs to provide detailed information about the vulnerability.
ステップ1:報告者は、脆弱性に関する詳細情報を提供する必要があります。
Step 2: Sinexcel checks and verifies the received vulnerability information and evaluates it.
ステップ2:Sinexcelは、受信した脆弱性情報を確認および検証し、評価します。
Step 3: Fix the vulnerability and verify the repair of our products.
ステップ3:脆弱性を修正し、当社製品の修正を検証します。
Step 4: Release a new version of the product for updates.
ステップ4:更新用の製品の新バージョンをリリースします。
Step 5: Reply to reporter with processing results.
ステップ5:報告者に処理結果を返信します。
Step 6: Monitor the stability of the product after the update.
ステップ6:更新後、製品の安定性を監視します。
The report will be confirmed within 3 working days upon receipt and an initial assessment will be conducted.
レポートは受領後3営業日以内に確認され、初期評価が実施されます。
Within 7 working days the assessment will be completed and the vulnerability will be fixed or a remediation plan developed.
7営業日以内に評価が完了し、脆弱性が修正されるか、修復計画が策定されます。
Critical vulnerabilities will be fixed within 3 working days after completion of assessment.
重大な脆弱性は、評価完了後3営業日以内に修正されます。
High risk vulnerabilities will be fixed within 7 working days after completing the assessment.
高リスクの脆弱性は、評価完了後7営業日以内に修正されます。
Medium risk vulnerabilities will be fixed within 30 working days after completing the assessment.
中リスクの脆弱性は、評価完了後30営業日以内に修正されます。
Low-risk vulnerabilities will be fixed within 60 working days after completing the assessment.
低リスクの脆弱性は、評価完了後60営業日以内に修正されます。
Certain vulnerabilities are subject to environmental or hardware limitations, and the final repair time will be based on the actual situation.
特定の脆弱性は、環境またはハードウェアの制限を受ける場合があり、最終的な修正時間は実際の状況に基づきます。
A separate emergency security bulletin is issued for severe or significant impact vulnerabilities.
深刻または重大な影響を与える脆弱性については、別途緊急セキュリティ情報が発行されます。
According to the degree of harm of vulnerabilities, they are divided into four levels: extreme risk, high risk, medium risk and low risk. When we receive a vulnerability report, we take a series of steps to resolve it internally with reference to ISO/IEC 30111. All reported vulnerabilities are scored according to the Common Vulnerability Scoring System CVSS 3.1 criteria.
脆弱性の被害の程度に応じて、極めて高いリスク、高リスク、中リスク、低リスクの4つのレベルに分類されます。脆弱性レポートを受け取った際、ISO/IEC 30111を参照し、内部で解決するための一連の措置を講じます。報告されたすべての脆弱性は、共通脆弱性評価システム(CVSS 3.1)の基準に従ってスコアリングされます。
Remote direct access to system permissions (server permissions, client permissions, smart devices) vulnerabilities, including but not limited to arbitrary code execution, arbitrary command execution, uploading and utilizing WebShell Trojans.
システム権限(サーバー権限、クライアント権限、スマートデバイス)へのリモート直接アクセス脆弱性(任意のコード実行、任意のコマンド実行、WebShellトロイの木馬のアップロードと利用を含むがこれらに限定されない)。
The core business system has logical design defects, including but not limited to any account password modification without any protection restrictions, any account login, etc.
コアビジネスシステムには、保護制限なしでのアカウントパスワードの変更、任意のアカウントログインなど(ただしこれらに限定されない)の論理設計上の欠陥があります。
It directly leads to serious information leakage vulnerabilities in the online business system, including but not limited to SQL injection vulnerabilities in the core DB.
これは、オンラインビジネスシステムにおける深刻な情報漏洩の脆弱性(コアDBのSQLインジェクション脆弱性を含むがこれに限定されない)に直接つながります。
Mobile terminal: Remote code execution vulnerability that can directly affect a large number of users without interaction.
モバイル端末:相互作用なしに多数のユーザーに直接影響を与える可能性のあるリモートコード実行の脆弱性。
Device side: Remote access to device execution permissions (such as downloading other user data, remote access to devices, etc.) in the Internet environment, there is no interactive remote command execution vulnerability in the Internet environment.
デバイス側:インターネット環境におけるデバイス実行権限へのリモートアクセス(他のユーザーデータのダウンロード、デバイスへのリモートアクセスなど)。インターネット環境においてインタラクティブなリモートコマンド実行の脆弱性はありません。
Vulnerabilities that directly lead to the leakage of sensitive information on online servers are including but not limited to core system source code leakage, server sensitive log file download, etc.
オンラインサーバー上の機密情報の漏洩に直接つながる脆弱性には、コアシステムのソースコードの漏洩、サーバーの機密ログファイルのダウンロードなどが含まれますが、これらに限定されません。
The core business system can use the identity of others to perform all functions of the vulnerability, the core business system important or sensitive unauthorized operation vulnerability.
コアビジネスシステムが他人のIDを使用してすべての機能を実行できる脆弱性。コアビジネスシステムの重要または機密の不正操作の脆弱性。
Unauthorized access to the management platform and use of administrator functions, including but not limited to sensitive background administrator account login, the activity of the relevant platform, user base, functional importance, and user information sensitivity will be considered as high risk vulnerability rating criteria.
管理プラットフォームへの不正アクセスおよび管理者機能の使用(機密性の高いバックグラウンド管理者アカウントのログインを含むがこれに限定されない)。関連プラットフォームの活動、ユーザーベース、機能の重要性、およびユーザー情報の機密性が、高リスク脆弱性の評価基準として考慮されます。
High risk information leakage vulnerability. Including but not limited to sensitive data leakage that can be directly exploited, leakage vulnerabilities that can lead to a large amount of user identity information.
高リスクの情報漏洩脆弱性。直接悪用される可能性のある機密データの漏洩、大量のユーザーID情報につながる可能性のある漏洩脆弱性を含みますが、これらに限定されません。
SSRF vulnerabilities with echoes that can access the Sinexcel Intranet.
Sinexcelイントラネットにアクセスできるエコーを伴うSSRFの脆弱性。
Mobile terminal: Third-party applications use mobile client functions across applications to perform high-risk operations (such as file read and write, SMS read and write, and client data read and write), and high-risk sensitive information leakage.
モバイル端末:サードパーティアプリケーションが、アプリケーション間でモバイルクライアント機能を使用して高リスクの操作(ファイルの読み書き、SMSの読み書き、クライアントデータの読み書きなど)を実行し、高リスクの機密情報が漏洩します。
Device: obtains device execution permission (such as downloading other user data or remotely accessing devices) from the near source or LAN. There is no interactive remote command execution vulnerability in the near source or LAN.
デバイス:近隣のソースまたはLANからデバイスの実行権限(他のユーザーデータのダウンロードやデバイスへのリモートアクセスなど)を取得します。近隣のソースまたはLANにインタラクティブなリモートコマンド実行の脆弱性はありません。
Device: Vulnerabilities that remotely cause permanent denial of service on devices are including but not limited to remote denial of service attacks on system devices (devices can no longer be used, completely permanently damaged, or the entire system needs to be rewritten), and attacks do not allow physical contact with devices, and attacks need to be quickly replicated in batches.
デバイス:デバイス上でリモートから永続的なサービス拒否(DoS)を引き起こす脆弱性には、システムデバイスに対するリモートサービス拒否攻撃(デバイスが使用不能になる、完全に永久的に損傷する、またはシステム全体を書き換える必要がある)が含まれますが、これらに限定されません。また、攻撃はデバイスとの物理的接触を許可せず、バッチで迅速に複製される必要があります。
Ordinary information leakage, including but not limited to mobile client plaintext storage password, containing server or database sensitive information source code compression package download, etc.
一般的な情報漏洩。これには、モバイルクライアントの平文ストレージパスワード、サーバーまたはデータベースの機密情報を含むソースコード圧縮パッケージのダウンロードなどが含まれますが、これらに限定されません。
The logical design defects existing in the system, such as defects in the temperature protection logic design, etc.
システムに存在する論理設計の欠陥(温度保護論理設計の欠陥など)。
SSRF vulnerability without echo.
エコーのないSSRFの脆弱性。
Vulnerabilities that require interaction to obtain user identity information, including but not limited to CSRF for sensitive operations, storage XSS, JSONP hijacking for sensitive information, etc.
ユーザーのID情報を取得するためにインタラクションを必要とする脆弱性。これには、機密操作に対するCSRF、蓄積型XSS、機密情報に対するJSONPハイジャッキングなどが含まれますが、これらに限定されません。
Remote denial-of-service vulnerability that can disable some functionality of an online application (need to be proven to affect other users).
オンラインアプリケーションの一部の機能を無効にする可能性のあるリモートサービス拒否脆弱性(他のユーザーに影響を与えることが証明される必要があります)。
A vulnerability that causes a smart device to deny service. For example, a system device is subjected to a locally initiated permanent denial-of-service attack (the device can no longer be used: completely permanently damaged or the entire operating system needs to be rewritten ), a temporary denial-of-service attack vulnerability caused by remote attacks (remote suspension or restart), and the attack needs to be able to quickly replicate in batches.
スマートデバイスのサービス拒否を引き起こす脆弱性。たとえば、システムデバイスがローカルで開始された永続的なサービス拒否攻撃(デバイスが使用不能になる:完全に永久的に損傷するか、オペレーティングシステム全体を書き換える必要がある)を受ける場合、またはリモート攻撃(リモートの停止または再起動)によって引き起こされる一時的なサービス拒否攻撃の脆弱性であり、攻撃はバッチで迅速に複製できる必要があります。
A vulnerability that allows ordinary business systems to use other people’s identities to perform all functional operations beyond their authority.
一般的なビジネスシステムが他人のIDを使用して、権限を超えたすべての機能操作を実行できるようにする脆弱性。
Vulnerabilities that can be exploited in phishing attacks, including but not limited to URL redirection vulnerabilities.
フィッシング攻撃で悪用される可能性のある脆弱性(URLリダイレクトの脆弱性を含むがこれに限定されない)。
Low-risk logic design flaws.
低リスクの論理設計の欠陥。
Minor information leakage vulnerabilities, including but not limited to path leaks, git file leaks, and server side business log contents.
軽微な情報漏洩の脆弱性(パスの漏洩、.gitファイルの漏洩、サーバー側のビジネスログの内容などを含むがこれらに限定されない)。
Vulnerabilities that can be exploited for phishing or hacking, including but not limited to arbitrary URL adjustments and reflective XSS vulnerabilities.
フィッシングやハッキングに悪用される可能性のある脆弱性(任意のURL調整や反射型XSSの脆弱性を含むがこれらに限定されない)。
Mobile terminal: local denial of service (including but not limited to denial of service caused by non-third-party component permissions), minor information leakage (only affecting individual users), etc.
モバイル端末:ローカルサービス拒否(サードパーティ以外のコンポーネント権限によって引き起こされるサービス拒否を含むがこれに限定されない)、軽微な情報漏洩(個々のユーザーにのみ影響する)など。
A vulnerability that causes a device to temporarily deny service. This includes but is not limited to temporary denial-of-service attack vulnerabilities caused by local attacks.
デバイスに一時的なサービス拒否を引き起こす脆弱性。これには、ローカル攻撃によって引き起こされる一時的なサービス拒否攻撃の脆弱性が含まれますが、これに限定されません。
Bug issues unrelated to security, including but not limited to slow opening of web pages, messy formats, etc.
セキュリティとは無関係のバグ問題(Webページの表示が遅い、フォーマットが乱れているなどを含むがこれらに限定されない)。
The submitted report is too simple and cannot be reproduced according to the content of the report, including but not limited to the vulnerabilities that cannot be reproduced even after repeated communication with the vulnerability auditor.
提出されたレポートが単純すぎて、レポートの内容に基づいて再現できない場合(脆弱性監査員と繰り返し連絡を取った後でも再現できない脆弱性を含むがこれに限定されない)。
Unexploitable or harmless reports, including but not limited to hoax CSRF (no real impact on users), local denial-of-service that cannot affect others, Self-XSS, PDF XSS, non-sensitive information leak (Intranet IP, domain name), mail bomb, etc.
悪用不可能または無害なレポート。これには、悪戯のCSRF(ユーザーへの実際の影響なし)、他人に影響を与えないローカルサービス拒否、Self-XSS、PDF XSS、機密ではない情報の漏洩(イントラネットIP、ドメイン名)、メールボムなどが含まれますが、これらに限定されません。
No practical source code leakage.
実用的なソースコードの漏洩はありません。
The security problem in the non-Sinexcel module of the hardware product, or the defect of the hardware itself.
ハードウェア製品の非Sinexcelモジュールにおけるセキュリティ問題、またはハードウェア自体の欠陥。
Security issues that Sinexcel proactively discloses or have been disclosed externally.
Sinexcelが自発的に開示している、または外部に開示されているセキュリティ問題。
Security issues on Products, apps or WEB applications that are no longer maintained.
メンテナンスされなくなった製品、アプリ、またはWEBアプリケーションのセキュリティ問題。
Vulnerabilities that Sinexcel is able to self-validate internally known and have been fixed.
Sinexcelが内部で既知であることを自己検証でき、すでに修正されている脆弱性。
Denial of service caused by permissions of third-party components.
サードパーティ製コンポーネントの権限によって引き起こされるサービス拒否。
Any information provided to Sinexcel about vulnerabilities in products, including all information in product vulnerability reports Information that you transfer will be owned and used by Sinexcel.
製品の脆弱性に関してSinexcelに提供された情報(製品の脆弱性レポートに含まれるすべての情報を含みます)は、Sinexcelによって所有および使用されます。
Sinexcel reserves the right to modify this policy at any time.
Sinexcelは、いつでも本ポリシーを変更する権利を留保します。