45466 policies in database
Link to program      
2016-07-21
2021-04-01
Stellantis logo
Thank
Gift
HOF
Reward

Reward

150 $ 

Stellantis

In mid-January 2021, Fiat Chrysler Automobiles (FCA) and PSA Groupe merged to create Stellantis, one of the world’s leading automakers and a mobility provider, guided by a clear vision: to offer freedom of movement with distinctive, affordable and reliable mobility solutions.

<https://www.stellantis.com/en>

Read more about Stellantis here:
<https://www.stellantis.com/en/news/press-releases/2021/january/stellantis-building-a-world-leader-in-sustainable-mobility>

Stellantis values engaging third party researchers to improve our products making them safer and more reliable. We have committed to formal recognition and compensation for discovery of reproducible and legitimate vulnerabilities, provided they are disclosed responsibly. Our goal with the Bug Bounty project is to foster a collaborative relationship with researchers to participate in responsible disclosure of vulnerabilities in Stellantis’ vehicles and connected services.

Responsible Disclosure Guidelines:

We will investigate legitimate reports and make every effort to correct any valid vulnerability as quickly as possible. In the spirit of encouraging responsible disclosure and reporting, we will not take legal action against nor ask law enforcement to investigate researchers participating in the program provided their compliance with the following Responsible Disclosure Guidelines:

  • Provide full details of the vulnerability, including information needed to reproduce and validate the issue by producing Proof of Concept (code, technical demos of vulnerability, or necessary steps needed to demonstrate your finding)
  • Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our services
  • Do not modify, access, or retain data that does not belong to you

Scope and rewards

Program rules

This program follows Bugcrowd’s standard disclosure terms.

For any testing issues (such as broken credentials, inaccessible application, or Bugcrowd Ninja email problems), please email support@bugcrowd.com. We will address your issue as soon as possible.

This program does not offer financial or point-based rewards for P5 — Informational findings. Learn more about Bugcrowd’s VRT.

In Scope

Scope Type Scope Name
android_application

https://play.google.com/store/apps/details?id=com.fcagroup.us.uconnect

android_application

https://play.google.com/store/apps/details?id=com.acn.uconnectmobile&hl=en

android_application

https://play.google.com/store/apps/details?id=com.acn.uc&hl=en

ios_application

https://itunes.apple.com/us/app/uconnect/id1229236724?mt=8

ios_application

https://itunes.apple.com/pl/app/panda-uconnect/id1117321678?mt=8

ios_application

https://itunes.apple.com/gb/app/uconnect-live/id881830261?mt=8

undefined

Vehicle Head Units, TPMS sensors, remote keyless entry, and any other system that is present in a hardware product that you own or are authorized to test against

web_application

www.driveuconnect.com

web_application

www.driveuconnect.eu

Out of Scope

Scope Type Scope Name
web_application

Any host/web property or products verified to be owned by Stellantis (domains/IP space/etc.) but not listed in Primary targets.


The progam has been crawled by Firebounty on 2016-07-21 and updated on 2021-04-01, 558 reports have been received so far.

FireBounty © 2015-2024

Legal notices | Privacy policy