CVE-2022-50788

EUVD-2022-55938
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive log files. Attackers can directly browse the /log directory to retrieve system and sensitive information without authentication.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
VulnCheckCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 66%
Affected Products (NVD)
VendorProductVersion
sound4first_firmware
2.15
sound4first_firmware
1.69
sound4impact_eco_firmware
1.16
sound4pulse_eco_firmware
1.16
sound4big_voice4_firmware
1.2
sound4big_voice2_firmware
1.30
sound4wm2_firmware
1.11
sound4impact_firmware
2.15
sound4impact_firmware
1.69
sound4pulse_firmware
2.15
sound4pulse_firmware
1.69
sound4stream_extension
2.4.29
𝑥
= Vulnerable software versions