---
id: CVE-2022-50692
title: >-
  SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Insufficient Session Expiration
  Vulnerability
summary: >-
  SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an insufficient
  session expiration vulnerability that allows attackers to reuse old session
  credentials. Attackers can exploit weak session management to potentially
  hijack act…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cvssSource: cna
cwe:
  - CWE-613
vendor: SOUND4 Ltd.
product: Impact/Pulse/First
affected:
  - 'Impact/Pulse/First Version 2: 1.1/2.15'
  - impact_pulse_eco 1.16
  - BigVoice4 1.2
  - BigVoice2 1.30
  - Stream 1.1/2.4.29
  - WM2 1.11
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-01-05T19:27:51.531478Z'
exploitAvailable: true
published: '2025-12-30'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T19:19:04.509Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2022-50692'
references:
  - url: 'https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5724.php'
    label: Zero Science Lab Disclosure (ZSL-2022-5724)
  - url: >-
      https://packetstormsecurity.com/files/170251/SOUND4-IMPACT-FIRST-PULSE-Eco-2.x-Insufficient-Session-Expiration.html
    label: Packet Storm Security Exploit Entry
  - url: 'https://cxsecurity.com/issue/WLB-2022120030'
    label: CXSecurity Vulnerability Listing
  - url: 'https://exchange.xforce.ibmcloud.com/vulnerabilities/247956'
    label: IBM X-Force Vulnerability Exchange
  - url: 'https://www.sound4.com/'
    label: SOUND4 Product Homepage
  - url: >-
      https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-insufficient-session-expiration-vulnerability
    label: >-
      VulnCheck Advisory: SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Insufficient
      Session Expiration Vulnerability
tags:
  - cve.org
  - exploit-available
epss: 0.00585
epssPercentile: 0.45957
ingestedAt: '2026-10-01T19:58:57.582Z'
---

## Overview

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an insufficient session expiration vulnerability that allows attackers to reuse old session credentials. Attackers can exploit weak session management to potentially hijack active user sessions and gain unauthorized access to the application.

## Affected

- `Impact/Pulse/First Version 2: 1.1/2.15`
- `impact_pulse_eco 1.16`
- `BigVoice4 1.2`
- `BigVoice2 1.30`
- `Stream 1.1/2.4.29`
- `WM2 1.11`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
