ZeroHour

CVE-2022-50696

PoC ×2
CVSS 4.0
9.3 critical
EPSS
<1%p46
Published
()
Modified
Description

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cannot be modified through normal device operations. Attackers can leverage these static credentials to gain unauthorized access to the device across Linux and Windows distributions without requiring user interaction.

Vendors
sound4
Products
first firmware, impact eco firmware, pulse eco firmware, big voice4 firmware, big voice2 firmware, wm2 firmware, impact firmware, pulse firmware, stream extension
Weakness
CWE-798
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.