9.8

CVE-2022-50794

Exploit

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Command Injection via Username

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the username parameter. Attackers can exploit index.php and login.php scripts by injecting arbitrary shell commands through the HTTP POST 'username' parameter to execute system commands.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sound4 ≫ Impact Firmware Version 2.15
   Sound4 ≫ Impact Version 2.0
Sound4 ≫ Impact Firmware Version 1.69
   Sound4 ≫ Impact Version 1.0
Sound4 ≫ Pulse Firmware Version 2.15
   Sound4 ≫ Pulse Version 2.0
Sound4 ≫ Pulse Firmware Version 1.69
   Sound4 ≫ Pulse Version 1.0
Sound4 ≫ First Firmware Version 2.15
   Sound4 ≫ First Version 2.0
Sound4 ≫ First Firmware Version 1.69
   Sound4 ≫ First Version 1.0
Sound4 ≫ Impact Eco Firmware Version 1.16
   Sound4 ≫ Impact Eco Version -
Sound4 ≫ Pulse Eco Firmware Version 1.16
   Sound4 ≫ Pulse Eco Version -
Sound4 ≫ Big Voice4 Firmware Version 1.2
   Sound4 ≫ Big Voice4 Version -
Sound4 ≫ Big Voice2 Firmware Version 1.30
   Sound4 ≫ Big Voice2 Version -
Sound4 ≫ Wm2 Firmware Version 1.11
   Sound4 ≫ Wm2 Version -
Sound4 ≫ Stream Extension Version 2.4.29
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.39% 0.878
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
disclosure@vulncheck.com 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
disclosure@vulncheck.com 9.3 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

https://www.sound4.com/
Product
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5739.php
Third Party Advisory
Exploit
https://packetstormsecurity.com/files/170266/SOUND4-IMPACT-FIRST-PULSE-Eco-2.x-username-Command-Injection.html
Third Party Advisory
Exploit
VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/247914
Third Party Advisory
https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-unauthenticated-command-injection-via-username
Third Party Advisory