7.5
CVE-2022-50695
- EPSS 0.77%
- Veröffentlicht 30.12.2025 22:41:34
- Zuletzt bearbeitet 16.01.2026 19:16:10
- Erkennungen
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x ICMP Flood Attack via Network Commands
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains a network vulnerability that allows unauthenticated attackers to send ICMP signals to arbitrary hosts through network command scripts. Attackers can abuse ping.php, traceroute.php, and dns.php to generate network flooding attacks targeting external hosts.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sound4 ≫ Impact Firmware Version 2.15
Sound4 ≫ Impact Firmware Version 1.69
Sound4 ≫ Pulse Firmware Version 2.15
Sound4 ≫ Pulse Firmware Version 1.69
Sound4 ≫ First Firmware Version 2.15
Sound4 ≫ First Firmware Version 1.69
Sound4 ≫ Impact Eco Firmware Version 1.16
Sound4 ≫ Pulse Eco Firmware Version 1.16
Sound4 ≫ Big Voice4 Firmware Version 1.2
Sound4 ≫ Big Voice2 Firmware Version 1.30
Sound4 ≫ Wm2 Firmware Version 1.11
Sound4 ≫ Stream Extension Version 2.4.29
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.77% | 0.526 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| disclosure@vulncheck.com | 8.7 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-770 Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
https://www.sound4.com/
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5728.php
https://packetstormsecurity.com/files/170255/SOUND4-IMPACT-FIRST-PULSE-Eco-2.x-ICMP-Flood-Attack.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/247948
https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-icmp-flood-attack-via-network-commands