Vulnerability Details CVE-2022-50792
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive system files. Attackers can exploit the vulnerability by manipulating the 'file' GET parameter to disclose arbitrary files on the affected device.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 42.2%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2022-50792
-
cpe:2.3:a:sound4:stream_extension:2.4.29
-
cpe:2.3:h:sound4:big_voice2:-
-
cpe:2.3:h:sound4:big_voice4:-
-
cpe:2.3:h:sound4:first:1.0
-
cpe:2.3:h:sound4:first:2.0
-
cpe:2.3:h:sound4:impact:1.0
-
cpe:2.3:h:sound4:impact:2.0
-
cpe:2.3:h:sound4:impact_eco:-
-
cpe:2.3:h:sound4:pulse:1.0
-
cpe:2.3:h:sound4:pulse:2.0
-
cpe:2.3:h:sound4:pulse_eco:-
-
-
cpe:2.3:o:sound4:big_voice2_firmware:1.30
-
cpe:2.3:o:sound4:big_voice4_firmware:1.2
-
cpe:2.3:o:sound4:first_firmware:1.69
-
cpe:2.3:o:sound4:first_firmware:2.15
-
cpe:2.3:o:sound4:impact_eco_firmware:1.16
-
cpe:2.3:o:sound4:impact_firmware:1.69
-
cpe:2.3:o:sound4:impact_firmware:2.15
-
cpe:2.3:o:sound4:pulse_eco_firmware:1.16
-
cpe:2.3:o:sound4:pulse_firmware:1.69
-
cpe:2.3:o:sound4:pulse_firmware:2.15
-
cpe:2.3:o:sound4:wm2_firmware:1.11