Cybersecurity & Product Safety
Information in accordance to the Cyber Resilience Act (CRA)
The cybersecurity of our products is a top priority for us.
On this page, we inform our customers, in accordance with Regulation (EU) 2024/2847 – Cyber Resilience Act (CRA), about security-related events that may affect our products with digital elements.
This information is provided for transparency and risk mitigation and does not replace individual technical advice.
This information applies to products with digital elements that:
- contain software or firmware components, and
- have interfaces, networks or data connections.
Not every security-related event automatically results in customer information. Information is provided in particular when users are affected or when measures are required to reduce risk or ensure the safe use of the product.
We inform affected users, in particular, if
- an actively exploited vulnerability, or
- a severe security-related incident
has occurred and the use of our products may lead to a security risk.
The decision to provide customer information is made after a technical and organizational assessment of the individual case.
Where relevant, our customer information contains:
- a clear description of the matter,
- information on possible effects on the product,
- recommended measures to reduce risk,
- where applicable, information on further steps, such as updates.
For security reasons, we do not publish technical exploit details, source code or information that could facilitate misuse.
Customers are informed without undue delay once sufficient information about possible risks and suitable protective measures is available.
LEMKEN informs affected customers and users on a risk-based basis and as promptly as is appropriate after a reliable assessment.
Note: The statutory 24-hour and 72-hour deadlines relate to reporting obligations to the authorities. User information is provided on a risk-based basis and depends on the available findings and required protective measures.
Depending on the individual case, we inform:
- specifically affected customers, for example by email or service information,
- and/or additionally via this website, if individual notification is not possible or not appropriate.
The communication channel is selected on a risk-based basis, taking into account the reachability of the affected customers or users, the urgency, the possible impact and the available countermeasures.
Security updates are provided during the respective support period via the update channels intended for the relevant product. This ensures that affected products are updated promptly and can continue to be used securely.
If you suspect a security-related vulnerability in one of our products, we ask you to report it responsibly via our security contact.
Email: productsecurity@lemken.com
To ensure fast and structured processing of your report, we recommend using our contact form for security reports [Link zum Kontaktformular]. This helps us capture all information required for assessment in full.
Please provide the following information wherever possible:
- Description of the vulnerability: Briefly and clearly describe what was observed, which vulnerability is suspected and which functions or processes may be affected.
- Affected product: Identify the affected product as precisely as possible, including product name, model, software or firmware version and, where relevant, serial number or affected component.
- Steps to reproduce: If known, describe step by step how the vulnerability can be reproduced and under which conditions it occurs.
- Technical classification: If possible, specify the affected interface, component or software function and add known technical references, such as a CWE classification.
- Impact and severity: Describe the suspected impact or risks, for example data access, manipulation, loss of function or product disruption, and add a severity assessment if available, for example based on CVSS or a plausible attack scenario.
- Active exploitation and disclosure: Please indicate whether there are signs of active or malicious use, whether the vulnerability has already been disclosed or whether other parties have already been informed.
- Evidence and tools used: Where available, add relevant conditions, log files, screenshots, network traces, proof-of-concept material or results from automated tools and scans.
- Contact and further communication: Please indicate how we can reach you for follow-up questions and whether you would like feedback on the processing status or optional acknowledgement, where legally and organizationally possible.
We treat all reports confidentially in accordance with our privacy policy and review them according to our Product Security process. After receiving your report, you will receive an acknowledgement where possible and may be contacted if follow-up questions are required.
NOTE:
-
Please use the provided email address and linked contact form exclusively to report possible security-related vulnerabilities or security incidents affecting LEMKEN products, software, apps, digital services or related components.
-
Please do not use this form for general IT disruptions, data protection requests, spare parts or service requests, operating questions or other support cases without a specific security context. For these matters, please use the relevant LEMKEN contact options.
Further Information
We handle incoming vulnerability reports confidentially, in a structured manner and within the framework of our Product Security process. The aim is coordinated processing, assessment and, where necessary and possible, remediation of the reported vulnerability without creating unnecessary risks for customers, users or third parties.
Incoming security reports are recorded centrally and assessed consistently, regardless of whether they are submitted via the contact form or by email to the stated Product Security address. Information from service partners, suppliers or development partners is also included in this process if it relates to LEMKEN products or digital components.
After receiving a report, we will provide an acknowledgement where possible. Based on our Product Security process, we first check whether the information is sufficient to understand the affected product, affected component and possible impact. If necessary, we contact the reporting person for follow-up questions. We then assess the technical relevance, possible risks for users and any required measures such as workarounds, security updates or further customer information.
We use personal data and contact details exclusively to process the report, communicate with the reporting person and document the case in a traceable manner. Data is only transferred to third parties where this is necessary for review, remediation or compliance with legal obligations, or where the reporting person has expressly consented.
We expect reported vulnerabilities to be investigated responsibly and not misused. In particular, third-party data must not be altered, published or accessed without authorization. Likewise, no attacks should be carried out beyond what is necessary to demonstrate the vulnerability, such as social engineering, spam, brute-force attacks or denial-of-service attacks.
Where possible, we provide feedback on receipt and the processing status of the report. After completing the review, we inform the reporting person, where legally, organizationally and from a security perspective possible, about the result or next steps. Upon request, named acknowledgement or thanks for the responsible report may be reviewed, provided there are no legal or organizational reasons against it.
Personal data is stored only for as long as necessary to process the report, document the case and fulfil legal obligations. Further information can be found in our Privacy Policy.
Further Information
For products with digital elements, LEMKEN provides security-related updates or other remedial measures during the respective intended support period, where this is necessary and technically possible to address confirmed vulnerabilities.
Information on the product-specific support period, including the end date of security support, is provided in the respective product documentation.
The information provided does not constitute any assurance, warranty or obligation beyond statutory or contractual provisions.
The applicable legal provisions and individual contractual agreements remain authoritative. Specific product, service or update notices remain unaffected.
This page is updated in the event of security-relevant events and regulatory changes.
Last updated: 09/2026
Note
Please use the provided contact form exclusively to report possible security-related vulnerabilities or security incidents affecting LEMKEN products, software, apps, digital services or related components.
Please do not use this form for general IT disruptions, data protection requests, spare parts or service requests, operating questions or other support cases without a specific security context. For these matters, please use the relevant LEMKEN contact options.
Glossary: Simple Explanations of CRA Terms
The CE marking indicates that the manufacturer has assessed the product and declares that it meets the applicable EU requirements. It is not a quality seal and does not guarantee that a security vulnerability can never occur.
The CRA is an EU regulation for digital products. It requires manufacturers to protect their connected machines, devices and software against cyberattacks. The requirements apply during development and for a defined period after the product has been sold.
A cybersecurity risk describes the danger that a digital attack may cause damage. Examples include machine downtime, manipulated settings, lost data or unauthorized access to an agricultural business.
An end customer is the person or business that uses a product itself and does not resell it. In the agricultural sector, this may for example be a farmer using a connected machine, an operating terminal or an app for their business.
With the EU Declaration of Conformity, the manufacturer confirms in writing that its product complies with the applicable EU legislation. The document specifies, among other things, the product, the manufacturer and the legal requirements taken into account.
The manufacturer develops or produces the product. The importer places a product from a non-EU country on the EU market. The distributor sells or supplies it further. All of them must ensure that the requirements of the CRA are complied with.
In the conformity assessment, the manufacturer checks whether the product fulfils all applicable legal requirements. This also includes cybersecurity requirements. Depending on the product, an independent assessment body may also be involved.
Authorities check whether products made available on the market meet the legal requirements. In the event of non-compliance, they may require corrective action, restrict sales or order product recalls.
Manufacturers must report certain severe security incidents and actively exploited vulnerabilities to the competent authorities. Affected users must also be informed if they need to take measures to protect themselves.
This is a device or software that processes data and connects directly or indirectly to other devices or networks. Examples include connected agricultural machinery, operating terminals, sensors, apps or digital control units.
An SBOM is a structured list of the software components of a product. It helps the manufacturer identify whether a component used contains a known security vulnerability. For farmers, this list is usually not directly relevant.
A vulnerability is a security weakness in a device or program. Attackers could use it to read data, change functions or disrupt the product. If a vulnerability is already being used for attacks, it is considered actively exploited.
A security update is an update that closes known security vulnerabilities. It should be installed as promptly as possible. This helps keep the product better protected against attacks and allows it to continue being used securely.
Hardware refers to the physical parts of a digital product, such as a terminal, sensor or control unit. Software refers to the programs running on it. Both may contain vulnerabilities and therefore need to be protected and updated where necessary.
The support period is the time during which the manufacturer monitors security vulnerabilities and provides necessary security updates for products made available on the EU market. The duration of this period depends, among other things, on how long the product is expected to be used. If your LEMKEN machine already falls within the period during which the CRA applies to the product or was manufactured after its date of application, the applicable support period is stated in the corresponding operating manual.
Economic operators are all companies that manufacture a digital product, import it from a non-EU country or sell it. Depending on their role, they bear different responsibilities for ensuring that the product is secure and meets the legal requirements.