{"id":"CVE-2022-50788","title":"SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Information Disclosure via Log Directory","summary":"SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive log files. Attackers can directly browse the /log directory to retrieve system and sensitive i…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cvssSource":"cna","cwe":["CWE-548"],"vendor":"SOUND4 Ltd.","product":"Impact/Pulse/First","affected":["Impact/Pulse/First Version 2: 1.1/2.15","impact_pulse_eco 1.16","BigVoice4 1.2","BigVoice2 1.30","Stream 1.1/2.4.29","WM2 1.11"],"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-01-05T19:34:46.699842Z"},"exploitAvailable":true,"published":"2025-12-30","updated":"2026-10-01","sourceUpdated":"2026-10-01T19:19:07.760Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2022-50788","references":[{"url":"https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5732.php","label":"Zero Science Lab Disclosure (ZSL-2022-5732)"},{"url":"https://packetstormsecurity.com/files/170259/SOUND4-IMPACT-FIRST-PULSE-Eco-2.x-Information-Disclosure.html","label":"Packet Storm Security Exploit Details"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/247921","label":"IBM X-Force Vulnerability Exchange Entry"},{"url":"https://www.sound4.com/","label":"SOUND4 Product Homepage"},{"url":"https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-information-disclosure-via-log-directory","label":"VulnCheck Advisory: SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Information Disclosure via Log Directory"}],"tags":["cve.org","exploit-available"],"epss":0.00833,"epssPercentile":0.56085,"ingestedAt":"2026-10-01T19:58:57.580Z","slug":"CVE-2022-50788","body":"## Overview\n\nSOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive log files. Attackers can directly browse the /log directory to retrieve system and sensitive information without authentication.\n\n## Affected\n\n- `Impact/Pulse/First Version 2: 1.1/2.15`\n- `impact_pulse_eco 1.16`\n- `BigVoice4 1.2`\n- `BigVoice2 1.30`\n- `Stream 1.1/2.4.29`\n- `WM2 1.11`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":53,"depthScoreParts":{"impact":41.3,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[]}