---
id: CVE-2022-50695
title: SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x ICMP Flood Attack via Network Commands
summary: >-
  SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains a network vulnerability
  that allows unauthenticated attackers to send ICMP signals to arbitrary hosts
  through network command scripts. Attackers can abuse ping.php, traceroute.php,
  and …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: cna
cwe:
  - CWE-770
vendor: SOUND4 Ltd.
product: Impact/Pulse/First
affected:
  - 'Impact/Pulse/First Version 2: 1.1/2.15'
  - impact_pulse_eco 1.16
  - BigVoice4 1.2
  - BigVoice2 1.30
  - Stream 1.1/2.4.29
  - WM2 1.11
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-02-18T21:20:23.820110Z'
exploitAvailable: true
published: '2025-12-30'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T19:19:05.860Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2022-50695'
references:
  - url: 'https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5728.php'
    label: Zero Science Lab Disclosure (ZSL-2022-5728)
  - url: >-
      https://packetstormsecurity.com/files/170255/SOUND4-IMPACT-FIRST-PULSE-Eco-2.x-ICMP-Flood-Attack.html
    label: Packet Storm Security Exploit Details
  - url: 'https://exchange.xforce.ibmcloud.com/vulnerabilities/247948'
    label: IBM X-Force Vulnerability Exchange
  - url: 'https://www.sound4.com/'
    label: SOUND4 Product Homepage
  - url: >-
      https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-icmp-flood-attack-via-network-commands
    label: >-
      VulnCheck Advisory: SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x ICMP Flood Attack
      via Network Commands
tags:
  - cve.org
  - exploit-available
epss: 0.00805
epssPercentile: 0.55153
ingestedAt: '2026-10-01T19:58:57.581Z'
---

## Overview

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains a network vulnerability that allows unauthenticated attackers to send ICMP signals to arbitrary hosts through network command scripts. Attackers can abuse ping.php, traceroute.php, and dns.php to generate network flooding attacks targeting external hosts.

## Affected

- `Impact/Pulse/First Version 2: 1.1/2.15`
- `impact_pulse_eco 1.16`
- `BigVoice4 1.2`
- `BigVoice2 1.30`
- `Stream 1.1/2.4.29`
- `WM2 1.11`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
