Security
Security advisories
Advisories for ProcessView+, ProcessView HV, the Remote PC MQTT Client, and the Server Software.
No advisories have been issued
No security advisories have been issued for any Chamber Data Hub product. This page exists so that there is a stable place to look, and so that it is already here when the first one is needed.
How you will be told
Nobody should have to poll a web page to find out whether their software needs attention. When an advisory is published:
- Registered security contacts are notified directly. If you have given us a named person or a monitored role address, we email them. If you have not, register one — it is the only reliable way we have to reach you.
- Distributors are notified separately, so they can reach the customers they supplied. We do not always know who those customers are; the distributor does.
- Release notes identify the release that carries the fix and link to the advisory, so a security fix is distinguishable from a feature change when you are deciding whether to schedule an update. See release notes.
What an advisory will contain
- Which products and versions are affected. The affected products and version ranges — and, just as importantly, which products are not affected. Ruling yourself out should be as quick as ruling yourself in.
- Impact and severity. What an attacker could actually do, what access they would need first, and how we rate the severity.
- What to do. The release that carries the fix, and the steps to apply it.
- What to do if you cannot update immediately. Validated environments do not update on demand. Where a configuration change, an access-control change, or a network control reduces the exposure in the meantime, we will say so.
- Whether records you have already produced are affected. If an issue could have affected a record that is already filed — a report, a signed document, an audit trail — we will say so, and we will describe how to recognize an affected one. This is the question an audit will ask, and it is not answered by "update to the latest version".
- Whether you can tell if you were affected. What evidence would exist on your system, and where to look for it. Where there is no reliable way to know, we will say that plainly rather than leave you to infer it.
Reporting a vulnerability
If you have found a security issue in one of our products, see our vulnerability disclosure policy for how to report it, what to include, and what happens next. You do not need to be a customer, and we will not ask you to sign an NDA.
For anything else, email support@chamberdatahub.com.