CVE-2022-50696
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cannot be modified through normal device operations.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.58%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cannot be modified through normal device operations. Attackers can leverage these static credentials to gain unauthorized access to the device across Linux and Windows distributions without requiring user interaction.
- CVSS 4.0
- 9.3 CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.58% probability · 46th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-798
- Affected
- sound4/first firmware · sound4/impact eco firmware · sound4/pulse eco firmware · sound4/big voice4 firmware · sound4/big voice2 firmware · sound4/wm2 firmware · sound4/impact firmware · sound4/pulse firmware · sound4/stream extension
- Source
- disclosure@vulncheck.com
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/247949Third Party Advisory
- https://packetstormsecurity.com/files/170256/SOUND4-IMPACT-FIRST-PULSE-Eco-2.x-Hardcoded-Credentials.htmlExploit, Third Party Advisory, VDB Entry
- https://www.sound4.com/Product
- https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-hardcoded-credentials-authentication-bypassThird Party Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5729.phpExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.