CVE-2022-50696
CRITICALDescription
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cannot be modified through normal device operations. Attackers can leverage these static credentials to gain unauthorized access to the device across Linux and Windows distributions without requiring user interaction.
Is your site exposed to CVE-2022-50696?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| sound4 | first_firmware |
| sound4 | first |
| sound4 | first_firmware |
| sound4 | first |
| sound4 | impact_eco_firmware |
| sound4 | impact_eco |
| sound4 | pulse_eco_firmware |
| sound4 | pulse_eco |
| sound4 | big_voice4_firmware |
| sound4 | big_voice4 |
| sound4 | big_voice2_firmware |
| sound4 | big_voice2 |
| sound4 | wm2_firmware |
| sound4 | wm2 |
| sound4 | impact_firmware |
| sound4 | impact |
| sound4 | impact_firmware |
| sound4 | impact |
| sound4 | pulse_firmware |
| sound4 | pulse |
| sound4 | pulse_firmware |
| sound4 | pulse |
| sound4 | stream_extension |
References
Exploits
Frequently Asked Questions
What is CVE-2022-50696? +
How severe is CVE-2022-50696? +
What products are affected by CVE-2022-50696? +
How do I check if I'm vulnerable to CVE-2022-50696? +
Related Vulnerabilities
Use of hard-coded credentials in KS-SOMED allowed an unauthorized attacker access to FTP server that hosted the application's update packages. …
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, when LightRAG is deployed with LIGHTRAG_API_KEY set but AUTH_ACCOUNTS unset, …
We observed that Intellispace Portal binaries doesn’t have any protection mechanisms to prevent reverse engineering. Specifically, the app’s code is …
Use of hard-coded, the same among all vulnerable installations SQLite credentials vulnerability in SIGNUM-NET FARA allows to read and manipulate …
An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token that could …
An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token that could …