8.8
CVE-2022-50793
- EPSS 2.9%
- Veröffentlicht 30.12.2025 22:41:38
- Zuletzt bearbeitet 13.01.2026 14:36:09
- Erkennungen
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Authenticated Command Injection via www-data-handler.php
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an authenticated command injection vulnerability in the www-data-handler.php script that allows attackers to inject system commands through the 'services' POST parameter. Attackers can exploit this vulnerability by crafting malicious 'services' parameter values to execute arbitrary system commands with www-data user privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sound4 ≫ Impact Firmware Version 2.15
Sound4 ≫ Impact Firmware Version 1.69
Sound4 ≫ Pulse Firmware Version 2.15
Sound4 ≫ Pulse Firmware Version 1.69
Sound4 ≫ First Firmware Version 2.15
Sound4 ≫ First Firmware Version 1.69
Sound4 ≫ Impact Eco Firmware Version 1.16
Sound4 ≫ Pulse Eco Firmware Version 1.16
Sound4 ≫ Big Voice4 Firmware Version 1.2
Sound4 ≫ Big Voice2 Firmware Version 1.30
Sound4 ≫ Wm2 Firmware Version 1.11
Sound4 ≫ Stream Extension Version 2.4.29
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.9% | 0.858 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| disclosure@vulncheck.com | 8.7 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
https://www.sound4.com/
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5737.php
https://packetstormsecurity.com/files/170264/SOUND4-IMPACT-FIRST-PULSE-Eco-2.x-services-Command-Injection.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/247917
https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-authenticated-command-injection-via-www-data-handlerphp