{"id":287530,"date":"2018-11-29T16:08:06","date_gmt":"2018-11-29T14:08:06","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=287530"},"modified":"2018-11-29T16:08:34","modified_gmt":"2018-11-29T14:08:34","slug":"major-security-flaw-in-sennheiser-headphone-software","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/287530-major-security-flaw-in-sennheiser-headphone-software.html","title":{"rendered":"Major security flaw in Sennheiser headphone software"},"content":{"rendered":"<p>German cybersecurity firm Secorvo Security Consulting has <a href=\"https:\/\/www.secorvo.de\/publikationen\/headsetup-vulnerability-report-secorvo-2018.pdf\" target=\"_blank\" rel=\"noopener\"><strong>discovered<\/strong><\/a> a major security flaw in the software bundled with Sennheiser headphones.<\/p>\n<p>The vulnerability is exclusive to Sennheiser&#8217;s HeadSetup and HeadSetup Pro software, and is enabled by the installation of root certificates.<\/p>\n<p>The software installed root certificates and encrypted private keys into the Trusted Root CA Certificate store, which could make the user&#8217;s system vulnerable to man-in-the-middle attacks.<\/p>\n<p>This means that attackers could potentially use this vulnerability to intercept and alter communications between two parties over a secure channel.<\/p>\n<p>Microsoft has implemented measures to invalidate the vulnerable certificates, and Sennheiser has released an updated version of its software suite which removes the vulnerability.<\/p>\n<p>This means that if users update their software and their Windows 10 installation, they should not be vulnerable to any exploits aimed at these certificates.<\/p>\n<p>Users can download the latest Sennheiser software suite from the company&#8217;s <a href=\"https:\/\/en-us.sennheiser.com\/headset-software-pc\" target=\"_blank\" rel=\"noopener\"><strong>official website<\/strong><\/a>.<\/p>\n<h3 class=\"my-4\">Now read:\u00a0<a href=\"https:\/\/mybroadband.co.za\/news\/security\/286918-gmail-bug-allows-senders-to-hide-their-identity.html\" rel=\"bookmark\">Gmail bug allows senders to hide their identity<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>German cybersecurity firm Secorvo Security Consulting has discovered a major security flaw in the software bundled with Sennheiser headphones.<\/p>\n","protected":false},"author":341028,"featured_media":186307,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[55918,15511,7859,31158],"class_list":["post-287530","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-headsetup","tag-security-flaw","tag-sennheiser","tag-software"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/287530"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341028"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=287530"}],"version-history":[{"count":0,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/287530\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/186307"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=287530"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=287530"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=287530"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}