

Policy 1
Hanwha Vision’s S-CERT*1 department is a team dedicated to addressing all possible security vulnerabilities of Hanwha Vision’s WISENET products and to responding promptly (analyzing and preparing countermeasures) in the event of a security vulnerability.
If your product is experiencing symptoms of a security vulnerability, please contact S-CERT (secure.cctv@hanwha.com) with detailed product information and instructions on how to reproduce the symptoms.
※ S-CERT does not respond to requests related to homepage (https://www.hanwhavision.com/) vulnerability, product support and feature requests.
Policy 2
Upon receipt of a security vulnerability report, a Security Breach Accident Countermeasures Council is convened immediately. Reporters of security vulnerabilities can receive an initial response within 2 business days, and can receive a response regarding the manufacturer’s future action and distribution plan related to the vulnerability within 10 business days.
Firmware with improved vulnerabilities and vulnerability details will not be disclosed until 90 days from receipt or until a date mutually agreed upon with the informant. For transparent and efficient management of security vulnerabilities, starting in September 2023, Hanwha Vision is participating in the CVE programme as a CNA that can directly register and manage CVE vulnerabilities, and is operating a bug bounty programme for internal customers.
Policy 3
The vulnerability-patched firmware is uploaded to the website along with the Vulnerability Report. Details of the vulnerability (vulnerability content, affected product information/firmware version, risk, countermeasures, etc.) are not disclosed until the patched firmware is released on the website to prevent zero-day attacks.
Details such as attack scenarios for vulnerabilities are not disclosed to prevent imitation attacks. If multiple products are affected by the vulnerability, corresponding firmware patches will be released simultaneously.

Add RSS Feed