CVE-2022-50692
7.5SOUND4 Ltd. · IMPACT, FIRST, PULSE, Eco, BigVoice4, BigVoice2, Stream, and Kantar Media WM2
Multiple SOUND4 audio processing products and Kantar Media WM2 contain an insufficient session expiration vulnerability that allows unauthenticated attackers to hijack active user sessions.
Executive summary
Several audio processing platforms are vulnerable to session hijacking due to insufficient session expiration, which allows unauthorized access to active user accounts.
Vulnerability
The vulnerability is an instance of insufficient session expiration (CWE-613) where the application fails to properly invalidate session tokens. This flaw allows an unauthenticated attacker to reuse older credentials to hijack active sessions and gain unauthorized access to the application.
Business impact
Successful exploitation of this vulnerability allows an attacker to gain unauthorized access to administrative or user interfaces without requiring valid credentials. This poses a significant risk of data compromise, unauthorized configuration changes to broadcast infrastructure, and potential reputational damage. Given the CVSS score of 7.5, this is considered a high-severity risk that demands immediate attention to prevent unauthorized control of critical audio processing systems.
Remediation
Immediate Action: Contact the vendor, SOUND4 Ltd., or Kantar Media to obtain the latest security updates, as an official patch version was not explicitly provided in the available data. If no patch is currently available, restrict access to the application management interface to trusted internal networks only.
Proactive Monitoring: Monitor system logs for unusual login patterns, concurrent session activity from disparate IP addresses, and unauthorized access attempts to the management console.
Compensating Controls: Deploy a Web Application Firewall (WAF) or equivalent network security control to restrict access to the web management interfaces, and implement strict source IP filtering to prevent unauthorized external access.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in the Packet Storm Security reference linked in the vulnerability details.
Analyst recommendation
This vulnerability presents a clear risk to the integrity and availability of broadcast audio infrastructure. Security teams should prioritize limiting exposure of these management interfaces immediately. Given the existence of a public proof-of-concept, it is critical to coordinate with the vendors to identify and apply the necessary security updates or configuration changes to ensure session tokens are properly invalidated.
Sources
Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.
- Zero Science Lab Disclosure (ZSL-2022-5724) Third-party advisory
- Packet Storm Security Exploit Entry Exploit / PoC
- CXSecurity Vulnerability Listing Third-party advisory
- IBM X-Force Vulnerability Exchange Vulnerability database entry
- SOUND4 Product Homepage
- VulnCheck Advisory: SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Insufficient Session Expiration Vulnerability Third-party advisory