This program encourages and rewards contributions by developers and security researchers who help make Arlo’s products more secure. Arlo provides monetary rewards and kudos for qualifying vulnerability submissions to this program. For submissions outside the scope of this program Arlo rewards Kudos points. Please click on the following link to the Arlo Kudos Rewards Program.
NETGEAR products have their own Bug Bounty program. Please click the following link to NETGEAR Cash Rewards Program.
For device testing, the following features are eligible for cash rewards:
Product | Firmware | Web Management | Client Apps | Cloud Infrastructure |
---|---|---|---|---|
Arlo Video Doorbell | X | X | X | X |
Arlo Security Light | X | X | X | X |
Arlo Bridge | X | X | X | X |
Arlo Pro 3 | X | X | X | X |
Arlo Pro 2 | X | X | X | X |
Arlo Pro | X | X | X | X |
Arlo | X | X | X | X |
Arlo Base Station | X | X | X | X |
Arlo Go | X | X | X | X |
Arlo Q | X | X | X | X |
Arlo Q+ | X | X | X | X |
Arlo Baby | X | X | X | X |
Arlo Ultra | X | X | X | X |
Arlo Andoid App | X | X | X | X |
Arlo iOS App | X | X | X | X |
Only vulnerabilities found in the latest version of the above are eligible. Targets listed below denote Cloud Infrastructure that support in-scope devices and are included in scope:
Last updated 16 Aug 2018 22:16:50 UTC
Technical severity | Reward range |
---|---|
p1 Critical | Up to: $1,200 |
p2 Severe | Up to: $600 |
p3 Moderate | Up to: $300 |
p4 Low | Up to: $150 |
P5 submissions do not receive any rewards for this program.
Target name | Type |
---|---|
Arlo Security Light |
IoT |
Arlo Bridge |
IoT |
Arlo Pro 3 |
IoT |
Arlo Pro 2 |
IoT |
Arlo Pro |
IoT |
Arlo |
IoT |
Arlo Base Station |
IoT |
Arlo Ultra |
IoT |
Arlo Go |
IoT |
Arlo Q |
IoT |
Arlo Q+ |
IoT |
Arlo Baby |
IoT |
Arlo iOS App |
iOS |
Arlo Android App |
Android |
Arlo Web App |
Website |
Arlo APIs |
API |
<https://www.arlo.com> |
Website |
<https://my.arlo.com> |
Website |
<https://updates.arlo.com/arlo> |
Website |
<https://arlo-device.messaging.arlo.com> |
Website |
<http://shop.arlo.com/> |
Website |
The Arlo Product Security team, at their sole discretion, determines the nature and impact of the vulnerabilities disclosed including, but not limited to, leveraging CVSS rating methodology to identify the appropriate payouts.
The first valid submission to alert Arlo of a previously unknown issue qualifies for reward. Arlo builds products using a common platform and framework. Multiple products sometimes inherit the same vulnerability. When determining bounty awards, Arlo grants a single award that accounts for all affected products.
Every calendar quarter Arlo gives awayArlo Pro 2s to the first 10 valid P1 findings and Arlo Security Lights to the first 10 valid P2 or P3 findings as a bonus.
Arlo rewards submissions that Arlo determines meets a below High Impact outcome. Arlo includes all products and services in scope for these rewards. Cash Rewards will be awarded based on the following:
$15,000
$10,000
Remote Unauthorized access to only a single Arlo account’s live video feed (via the publicly accessible internet - i.e. not on the same LAN)
In addition to these Terms and Conditions regarding the Arlo Responsible Disclosure Program (the "Program"), there may be additional restrictions depending upon applicable local laws.
ARLO RESERVES THE RIGHT TO MODIFY OR CANCEL THE ARLO RESPONSIBLE DISCLOSURE PROGRAM AT ANY TIME WITHOUT NOTICE. ALL PARTICIPANTS AND SUBMISSIONS ARE STRICTLY VOLUNTARY. THIS OFFER IS VOID WHERE PROHIBITED BY LAW AND IN PARTICIPATING, YOU MUST NOT VIOLATE ANY LAW. YOU ALSO MUST NOT DISRUPT ANY SERVICE OR COMPROMISE ANYONE’S DATA.
This bounty follows Bugcrowd’s Public Disclosure Policy.
Requests to disclose the results of a submission will be considered on a case by case basis and require explicit prior written consent from Arlo.
This program follows Bugcrowd’s standard disclosure terms.
This program does not offer financial or point-based rewards for P5 — Informational findings. Learn more about Bugcrowd’s VRT.
Scope Type | Scope Name |
---|---|
android_application | Arlo Android App |
api | Arlo APIs |
ios_application | Arlo iOS App |
undefined | Arlo Security Light |
undefined | Arlo Bridge |
undefined | Arlo Pro 3 |
undefined | Arlo Pro 2 |
undefined | Arlo Pro |
undefined | Arlo |
undefined | Arlo Base Station |
undefined | Arlo Ultra |
undefined | Arlo Go |
undefined | Arlo Q |
undefined | Arlo Q+ |
undefined | Arlo Baby |
web_application | Arlo Web App |
web_application | https://www.arlo.com |
web_application | https://my.arlo.com |
web_application | https://updates.arlo.com/arlo |
web_application | https://arlo-device.messaging.arlo.com |
web_application | http://shop.arlo.com/ |
This program have been found on Bugcrowd on 2018-05-29.
FireBounty © 2015-2024