The National Motor Freight Traffic Association, Inc.® (NMFTA)® is committed to improving cybersecurity across the commercial transportation ecosystem. In an effort to better protect our members, partners, customers, and the broader industry, we welcome information regarding potential security vulnerabilities affecting products, services, systems, and technologies used within the trucking and logistics sector.

This policy and advisory apply to products, services, applications, APIs, websites, and digital assets developed, maintained, or operated by NMFTA, as well as vulnerabilities reported to NMFTA involving commercial transportation technologies such as trucks, trailers, telematics devices, electronic logging devices (ELDs), fleet management systems, and distribution center technologies.

Third-party products or services not developed or managed by NMFTA may fall outside NMFTA’s direct remediation authority; however, NMFTA may coordinate disclosure efforts with affected vendors, manufacturers, researchers, industry partners, and other stakeholders where appropriate.

We are prepared to work with individuals who responsibly report security vulnerabilities to our attention and will acknowledge all relevant submissions. NMFTA will only validate reported vulnerabilities that are reproducible using supported or current versions of products, services, or software where applicable.

Vulnerabilities should be submitted to cve-coordination@nmfta.org and should include the following items:

  • Name of the product, service, application, device, or digital asset containing the vulnerability.
  • Product version, environment details, or relevant identifiers, if applicable.
  • A complete description of the vulnerability.
  • The steps required to reproduce the vulnerability, including any relevant logs, screenshots, packet captures, or proof-of-concept code.
  • A description of the potential impact of the vulnerability.

You will receive an acknowledgement of receipt of your vulnerability report within two (2) business days, an initial status update within seven (7) business days, and notification when the reported vulnerability has been remediated, coordinated, or otherwise addressed. Vulnerability reports will be kept confidential until remediation is completed or coordination is required with manufacturers, or other stakeholders.

NMFTA may not be able to evaluate submissions that are incomplete or that do not include the information requested above. If required information is not included, NMFTA will contact the submitting party and provide details on what information is required to re-submit.

By submitting a vulnerability report, you acknowledge and agree that the information provided may be used by NMFTA for the purposes of investigating, validating, remediating, coordinating, and communicating about reported security issues in accordance with NMFTA’s Privacy Policy and applicable legal requirements.

Disclosure Timelines

When NMFTA identifies or coordinates a confirmed vulnerability affecting products, services, or technologies within scope, NMFTA will assign or coordinate the assignment of a Common Vulnerabilities and Exposures (CVE) identifier where appropriate.

To help protect users and minimize exploitation risk, specific technical details, mitigations, or remediation guidance may be withheld until a validated fix, mitigation, or coordinated disclosure plan is available.

Upon release of a remediation, fix, mitigation, or coordinated disclosure, NMFTA may publish a Security Advisory outlining the nature of the vulnerability, potential impact, affected products or services, and recommended remediation steps or updates.

NMFTA may publish Security Advisories or Informational Articles to share information regarding security-related topics such as:

  • New security features or hardening improvements.
  • Product-specific security configuration guidance and best practices.
  • Security vulnerabilities affecting third-party components.
  • Installation instructions for applying security updates.
  • Information regarding dependencies, prerequisites, or compatibility issues that could impact products or services within the commercial transportation ecosystem.
  • Security related operational guidance for customers, partners, carriers, and industry stakeholders.

Customers, partners, manufacturers, carriers, and other stakeholders are encouraged to monitor NMFTA security communications and advisories regularly to ensure timely implementation of recommended updates and mitigations.