PT-2018-14084 · Sennheiser · Sennheiser Headsetup

Published

2018-11-09

·

Updated

2019-05-15

·

CVE-2018-17612

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Sennheiser HeadSetup version 7.3.4903
Description The issue allows remote attackers to spoof arbitrary web sites or software publishers by utilizing Certification Authority (CA) certificates placed in the Trusted Root CA store of the local system. The private key is published in the SennComCCKey.pem file within the public software distribution. This could enable spoofing even after the HeadSetup product is uninstalled. A vulnerability assessment should check for unwanted CA certificates with a CN of 127.0.0.1 or SennComRootCA on all Windows systems.
Recommendations For Sennheiser HeadSetup version 7.3.4903, remove any unwanted CA certificates with a CN of 127.0.0.1 or SennComRootCA from the Trusted Root CA store to prevent spoofing. As a temporary workaround, consider restricting access to the SennComCCKey.pem file until a patch is available.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-17612

Affected Products

Sennheiser Headsetup