CVE-2022-50696
CRITICAL Exploitation: PoC
9.8
CVSS 3.1
Description
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cannot be modified through normal device operations. Attackers can leverage these static credentials to gain unauthorized access to the device across Linux and Windows distributions without requiring user interaction.
Metadata
Severity & Metrics
9.8
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Affected products (6)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Kantar Media | WM2 | — | 1.11 |
| SOUND4 Ltd. | BigVoice2 | — | 1.30 |
| SOUND4 Ltd. | BigVoice4 | — | 1.2 |
| SOUND4 Ltd. | Impact/Pulse Eco | — | 1.16 |
| SOUND4 Ltd. | Impact/Pulse/First | — | Version 2: 1.1/2.15 |
| SOUND4 Ltd. | Stream | — | 1.1/2.4.29 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-798 | cna | Use of Hard-coded Credentials |
CVSS scores (2)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 9.8 | CRITICAL | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 9.3 | CRITICAL | 4.0 | cna | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
References (5)
- Zero Science Lab Disclosure (ZSL-2022-5729) https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5729.php
- Packet Storm Security Exploit Details https://packetstormsecurity.com/files/170256/SOUND4-IMPACT-FIRST-PULSE-Eco-2.x-Hardcoded-Credentials.html
- IBM X-Force Vulnerability Exchange Entry https://exchange.xforce.ibmcloud.com/vulnerabilities/247949
- SOUND4 Product Homepage https://www.sound4.com/
- VulnCheck Advisory: SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Hardcoded Credentials Authentication Bypass https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-hardcoded-credentials-authentication-bypass