Users who have installed the Sennheiser HeadSetup software are unaware that along with it they have also installed a root certificate in the Trusted Root CA Certificate store. Worse still, the software also installs an encrypted version of the certificate's private key, which is not as secure as the developers thought.
Like the Lenovo SuperFish fiasco, this certificate and its private key were the same for everyone who installed the software. Because of this, it could allow an attacker who was able to decrypt the private key to perform “Man-in-the-Middle” attacks.
While these certificate files are deleted when a user uninstalls the HeadSetup software, the trusted root certificate is not removed. This would allow an attacker who had the correct private key to continue to perform attacks even when the software is no longer installed on the computer.
According to a disclosure made today by security consulting firm Secorvo, these certificates were discovered when a random check of a computer's Trusted Root Certificate CA store was performed.
When HeadSetup is installed, two certificates are placed on the computer. These certificates are used by the software to communicate with the Headset, using an encrypted TLS web socket.
The first certificate named SennComCCCert.pem is the root certificate and SennComCCKey.pem is the private key for this certificate.
When the researchers analyzed the private key, they found that it was encrypted with AES-128-CBC encryption and needed to find the appropriate password to decrypt it. Since the HeadSetup program also needed to decrypt the key, it must have been stored somewhere, and in this case it was in a file called WBCCListener.dll.
“To decrypt the file we needed to know the encryption algorithm and the key that the manufacturer used for encryption,” the researchers explained. “Our first guess was that the provider used the common AES encryption algorithm with a 128-bit key in CBC mode. In the HeadSetup installation directory we found only one piece of executable code containing the filename SennComCCKey.pem, a DLL file named WBCCListener.dll. We checked for “AES” in the strings contained in this DLL. There was indeed the algorithm identifier aes-128.cbc. We found that the key used by the provider had a close proximity to this algorithm identifier, clearly stored in the code.”
Once they decrypted the private key into a standard OpenSSL PEM they needed a passphrase to use it. This passphrase was located in a configuration file called WBCCServer.properties.
Now that they had access to the private key for the root certificate, they were able to create a wild card certificate.
Since this certificate was created using the same private key found on any computer that installed the same version of HeadSetup, those other computers would also be vulnerable to this certificate. It could then be used by an attacker to perform a man-in-the-middle attack.
Attackers could just as easily create certificates to carry out attacks on banks in order to steal login credentials, credit card information, or other sensitive data.
Removing the insecure root certificate
Secorvo had previously disclosed this vulnerability to Sennheiser and assigned the unique ID CVE-2018-17612. Sennheiser said an updated version of its HeadSetup software would be released by the end of November. When installed, the update will remove root certificates and ensure that no certificates are left behind when the software is uninstalled.
In the meantime, Sennheiser has released information that can be used to remove the certificates for those who want to protect themselves immediately. It is recommended that all HeadSetup users download and perform these actions to remove the vulnerable certificates.
Microsoft has also published security advisory ADV180029 titled “Inadvertently Disclosed Digital Certificates Could Allow Spoofing,” which explains that Microsoft has released an updated list of trusted certificates that removes trust for these certificates.
