7.5

CVE-2022-50788

Exploit

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Information Disclosure via Log Directory

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive log files. Attackers can directly browse the /log directory to retrieve system and sensitive information without authentication.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sound4 ≫ First Firmware Version 2.15
   Sound4 ≫ First Version 2.0
Sound4 ≫ First Firmware Version 1.69
   Sound4 ≫ First Version 1.0
Sound4 ≫ Impact Eco Firmware Version 1.16
   Sound4 ≫ Impact Eco Version -
Sound4 ≫ Pulse Eco Firmware Version 1.16
   Sound4 ≫ Pulse Eco Version -
Sound4 ≫ Big Voice4 Firmware Version 1.2
   Sound4 ≫ Big Voice4 Version -
Sound4 ≫ Big Voice2 Firmware Version 1.30
   Sound4 ≫ Big Voice2 Version -
Sound4 ≫ Wm2 Firmware Version 1.11
   Sound4 ≫ Wm2 Version -
Sound4 ≫ Impact Firmware Version 2.15
   Sound4 ≫ Impact Version 2.0
Sound4 ≫ Impact Firmware Version 1.69
   Sound4 ≫ Impact Version 1.0
Sound4 ≫ Pulse Firmware Version 2.15
   Sound4 ≫ Pulse Version 2.0
Sound4 ≫ Pulse Firmware Version 1.69
   Sound4 ≫ Pulse Version 1.0
Sound4 ≫ Stream Extension Version 2.4.29
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.77% 0.526
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
disclosure@vulncheck.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
disclosure@vulncheck.com 6.9 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-548 Exposure of Information Through Directory Listing

The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.

https://www.sound4.com/
Product
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5732.php
Third Party Advisory
Exploit
https://packetstormsecurity.com/files/170259/SOUND4-IMPACT-FIRST-PULSE-Eco-2.x-Information-Disclosure.html
Third Party Advisory
Exploit
VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/247921
Third Party Advisory
https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-information-disclosure-via-log-directory
Third Party Advisory