Vulnerability record · CVE-2018-17612 · published 9 November 2018
CVE-2018-17612: Sennheiser headsetup improper certificate validation vulnerability
Sennheiser · Headsetup
Sennheiser HeadSetup 7.3.4903 places Certification Authority (CA) certificates into the Trusted Root CA store of the local system, and publishes the private key in the SennComCCKey.pem file within the public software distribution, which allows remote attackers to spoof arbitrary web sites or software publishers for several years, even if the HeadSetup product is uninstalled. NOTE: a vulnerability-assessment approach must check all Windows systems for CA certificates with a CN of 127.0.0.1 or SennComRootCA, and determine whether those certificates are unwanted.
Description
Sennheiser HeadSetup 7.3.4903 places Certification Authority (CA) certificates into the Trusted Root CA store of the local system, and publishes the private key in the SennComCCKey.pem file within the public software distribution, which allows remote attackers to spoof arbitrary web sites or software publishers for several years, even if the HeadSetup product is uninstalled. NOTE: a vulnerability-assessment approach must check all Windows systems for CA certificates with a CN of 127.0.0.1 or SennComRootCA, and determine whether those certificates are unwanted.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/106045 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV180029 | PatchVendor Advisory |
| https://www.secorvo.de/publikationen/headsetup-vulnerability-report-secorvo-2018.pdf | ExploitMitigationTechnical DescriptionThird Party Advisory |
| http://www.securityfocus.com/bid/106045 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV180029 | PatchVendor Advisory |
| https://www.secorvo.de/publikationen/headsetup-vulnerability-report-secorvo-2018.pdf | ExploitMitigationTechnical DescriptionThird Party Advisory |
Track CVE-2018-17612 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-17612), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.