Skip to navigation Skip to content
Report a Vulnerability

Report a Vulnerability

Please complete this form or email vulnerabilities@nrgsystems.com to report suspected security vulnerabilities.

Individuals are encouraged to report suspected vulnerabilities as soon as reasonably practicable, particularly where personal data, confidential information, authentication credentials, regulated information, or system availability may be affected. Prompt reporting assists NRG in assessing and, where required, complying with applicable legal, regulatory, contractual and data breach of notification obligations, including timeframes for assessing and notifying personal data breaches. This is without prejudice to any separate reporting, notification or escalation obligations that may apply under any contract, policy, law, regulation or duty owed to NRG or any other person.

Reports should include, where possible:

  • Affected products, URL, system, API, or service
  • The version of the product on which the vulnerability is present, or the specific configuration of the product that is vulnerable
  • Detailed description of the vulnerability, including the following information:
    • A summary of the vulnerability
    • Required steps to reproduce the vulnerability
    • Required configuration to reproduce the vulnerability
    • Possible mitigation measures for the vulnerability
  • Screenshots or supporting evidence, where appropriate
  • Vulnerability severity (self-assessment): Critical / High / Medium / Low / Informational
  • Potential impact assessment - what an attacker could do by exploiting this issue, and any evidence of real-world exploitation you're aware of
  • Whether any personal data, confidential information, or regulated information may have been exposed
  • Reporters contact details

NRG may request additional information to support investigation or validation of activities.  

We encourage submissions via this Coordinated Vulnerability Disclosure page where possible. Policy on Coordinated Vulnerability Disclosure

Contact information

Please fill out the form below and we will respond to your request.

  • Provide a detailed description of the vulnerability.
  • Include steps to reproduce the issue.
  • Include any relevant screenshots or files.
You may upload a file or screenshot to help illustrate the vulnerability.
Vulnerability severity (self-assessment) *