Security recommendations

Follow these recommendations to enhance the security of your devices.

Limit attack surfaces

It is good practice to limit the possible attack surfaces of a device to the absolute minimum needed to fulfill the requirements of the use case. To support this Sennheiser allows the configuration of:

  • 3rd party access – disabled by default
  • mDNS – enabled by default

Additionally, the user can opt out of using audio over IP (Dante®) by connecting the TeamConnect Ceiling Medium analog audio outputs instead.

Keep software up to date

Sennheiser releases firmware updates for security issues in a timely manner. Users of TeamConnect Ceiling Medium should keep their devices updated to the latest version. Control Cockpit is checking daily for new updates. The user can then update the device at their convenience.

Please always keep your systems up to date.

Use strong passwords

To protect control access over the network, you must choose a strong password with at least 10 characters that includes at least one of each of the following:
  • lowercase letter: a, b, c, …, x, y, z
  • uppercase letter: A, B, C, …, X, Y, Z
  • digit: 0, …, 9
  • at least one special character that is present on a standard US-layout keyboard: !#$%&()*+,-./:;<=>?@[]^_{|}~

To protect each individual user installation, whenever a TeamConnect Ceiling Medium is controlled over the network, the passwords used are chosen by the user.

It is recommended to use a unique password for each device, as well as separate passwords for access to 3rd party API.