AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-17612

HIGH · CVSS 7.5 EPSS 6.73%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-11-09 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. It affects Windows. It may be remotely exploitable.

CVE
CVE-2018-17612
Severity
HIGH
CVSS
7.5
EPSS
6.73%
Windows

Original NVD Description

Sennheiser HeadSetup 7.3.4903 places Certification Authority (CA) certificates into the Trusted Root CA store of the local system, and publishes the private key in the SennComCCKey.pem file within the public software distribution, which allows remote attackers to spoof arbitrary web sites or software publishers for several years, even if the HeadSetup product is uninstalled. NOTE: a vulnerability-assessment approach must check all Windows systems for CA certificates with a CN of 127.0.0.1 or SennComRootCA, and determine whether those certificates are unwanted.

Related CVEs

Other vulnerabilities affecting the same vendor(s)