Cybersecurity : Hanwha Techwin - Security Global Leader

Security Vulnerability Disclosure Policy

  • 1. Security Vulnerability Response Center
    (S-CERT)
    • Hanwha Techwin’s S-CERT*1 department is a team dedicated to address all possible security vulnerabilities of Hanwha Techwin’s WISENET products and to respond promptly (analyze and prepare countermeasure) in the event of a security vulnerability. If your product is experiencing symptoms of security vulnerability, please contact S-CERT (secure.cctv@hanwha.com) with detailed product information, and instructions on how to reproduce the symptoms.
      ※ S-CERT does not respond to requests related to product support and features. Please contact your Hanwha Sales Representative for general product inquiries.
    2. Security Vulnerability Response Process
    • Upon receipt of a security vulnerability report, a Security Breach Accident Countermeasures Council is convened immediately. The goal of the Council is to analyze the content and impact of the vulnerability, prepare the resolution for the issue, and post the patched firmware on the website as soon as possible.
    3. Security Vulnerability Notice Policy
    • The vulnerability patched firmware is uploaded to the website*2 together with the Vulnerability Report. The details of the vulnerability (vulnerability content, affected product information / firmware version, risk, countermeasures, etc.) are not disclosed until the patched firmware is released on the website for zero-day attack prevention. Details such as attach scenarios for vulnerabilities are not disclosed to prevent imitating attacks. If multiple products are affected by the vulnerability, corresponding firmware patches will be released concurrently.
    • * 1. S-CERT: Security-Computer Emergency Response Team
    • * 2. HQ - Cybersecurity page of the website (Technical Guide > Cybersecurity)
      HTA - Main page (with Vulnerability Report)
      HTE - Main page and dedicated web page
    RSS Feed
  • Cybersecurity Enhancement Activities
    • Long-term Firmware Support Policy for Cybersecurity

      • 보기
        View
      • Download
    • Cybersecurity Enhancement Activities

      • 보기
        View
      • Download
    Read more
  • Cybersecurity Guides
    • Wisenet7 Next level Cybersecurity

      • 보기
        View
      • Download
    • Mutual Authentication Guide for Devices

      • 보기
        View
      • Download
    • Network Hardening Guide_Camera

      • 보기
        View
      • Download
    • Hanwha Techwin Private Root CA Pre-Installation Guide

      • 보기
        View
      • Download
    • Network Hardening Guide_NVR

      • 보기
        View
      • Download
    • Guidelines for secure use of SNMP

      • 보기
        View
      • Download
    • Guidelines for secure use of ONVIF WS-Discovery

      • 보기
        View
      • Download
    • Cybersecurity – Securing Video Surveillance Devices

      • 보기
        View
      • Download
    Read more
  • Vulnerability Report
    • Log4j Vulnerability Report (CVE-2021-44228)

      • 보기
        View
      • Download
    • NVR Vulnerability Report (CVE-2017-7912)

      • 보기
        View
      • Download
    • Vulnerability Report for gSOAP

      • 보기
        View
      • Download
    • KRACK(Key Reinstallation Attack) Analysis Report – Hanwha Techwin

      • 보기
        View
      • Download
    • SmartCam Vulnerability Report

      • 보기
        View
      • Download
    • DVR Vulnerability Report

      • 보기
        View
      • Download
    • NVR Vulnerability Report (CVE-2019-12223)

      • 보기
        View
      • Download
    • NVR Vulnerability Report (CVE-2021-32934/ CVE-2021-28372)

      • 보기
        View
      • Download
    Read more
  • Pen Test Report
    • Penetration Test Report (Wisenet AI Network Video Recorders 25Models)

      • 보기
        View
      • Download
    • Penetration Test Report (Wisenet SSM 2.10.6)

      • 보기
        View
      • Download
    • Penetration Test Report (Wisenet X, P, Q, L Series Cameras)

      • 보기
        View
      • Download
    Read more