CVE-2023-53962
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated directory traversal vulnerability that allows remote attackers to write arbitrary files through the 'upgfile' parameter in upload.cgi.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.21%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated directory traversal vulnerability that allows remote attackers to write arbitrary files through the 'upgfile' parameter in upload.cgi. Attackers can exploit the vulnerability by sending crafted multipart form-data POST requests with directory traversal sequences to write files to unintended system locations.
- CVSS 4.0
- 8.8 HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 1.21% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- sound4/impact firmware · sound4/pulse firmware · sound4/first firmware · sound4/stream extension · sound4/wm2 firmware · sound4/big voice2 firmware · sound4/big voice4 firmware · sound4/pulse eco firmware · sound4/impact eco firmware
- Source
- disclosure@vulncheck.com
References
- https://web.archive.org/web/20221207074555/https://www.sound4.com/Product
- https://www.exploit-db.com/exploits/51172Exploit, Third Party Advisory, VDB Entry
- https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-unauthenticated-directory-traversal-file-writeThird Party Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5730.phpExploit, Third Party Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5730.phpExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.