Vulnerability Name: | CVE-2018-17612 (CCN-152942) | ||||||||||||
Assigned: | 2018-10-31 | ||||||||||||
Published: | 2018-10-31 | ||||||||||||
Updated: | 2019-05-15 | ||||||||||||
Summary: | Sennheiser HeadSetup 7.3.4903 places Certification Authority (CA) certificates into the Trusted Root CA store of the local system, and publishes the private key in the SennComCCKey.pem file within the public software distribution, which allows remote attackers to spoof arbitrary web sites or software publishers for several years, even if the HeadSetup product is uninstalled. Note: a vulnerability-assessment approach must check all Windows systems for CA certificates with a CN of 127.0.0.1 or SennComRootCA, and determine whether those certificates are unwanted. | ||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||||||
Vulnerability Type: | CWE-295 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2018-17612 Source: BID Type: Third Party Advisory, VDB Entry 106045 Source: CCN Type: Sennheiser Web site Headset Software Source: XF Type: UNKNOWN sennheiser-cve201817612-spoofing(152942) Source: MISC Type: Patch, Vendor Advisory https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV180029 Source: CCN Type: Secorvo Web site Certificate Management Vulnerability in Sennheiser HeadSetup Source: MISC Type: Exploit, Mitigation, Technical Description, Third Party Advisory https://www.secorvo.de/publikationen/headsetup-vulnerability-report-secorvo-2018.pdf | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |