ZeroHour

CVE-2022-50788

PoC ×2
CVSS 4.0
6.9 medium
EPSS
<1%p56
Published
()
Modified
Description

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive log files. Attackers can directly browse the /log directory to retrieve system and sensitive information without authentication.

Vendors
sound4
Products
first firmware, impact eco firmware, pulse eco firmware, big voice4 firmware, big voice2 firmware, wm2 firmware, impact firmware, pulse firmware, stream extension
Weakness
CWE-548
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.