CVE-2022-50788

7.5

SOUND4 Ltd. · IMPACT/FIRST/PULSE/Eco

SOUND4 products contain an information disclosure vulnerability allowing unauthenticated attackers to access sensitive log files via directory browsing.

Executive summary

An unauthenticated information disclosure vulnerability in multiple SOUND4 products allows remote attackers to access sensitive system logs, posing a significant risk to data confidentiality.

Vulnerability

This vulnerability is a directory listing flaw (CWE-548) that allows an unauthenticated, remote attacker to browse the /log directory. By accessing this endpoint, an attacker can retrieve sensitive system information without requiring any prior authentication or authorization.

Business impact

The exposure of system logs can lead to the leakage of sensitive configuration data, credentials, or operational details that facilitate further attacks. While the CVSS score of 7.5 indicates a high severity, the potential for an attacker to gain deep insight into the internal environment significantly increases the risk of a broader security compromise. Unauthorized access to these files may also result in regulatory non-compliance regarding data protection.

Remediation

Immediate Action: Contact the vendor immediately to obtain the appropriate security patches or firmware updates for your specific device model. If a patch is unavailable, restrict network access to the management interface of these devices to trusted management subnets only.

Proactive Monitoring: Monitor web access logs for unauthorized attempts to access directories or files within the /log path. Unusual spikes in traffic or requests for log files should be investigated as potential reconnaissance attempts.

Compensating Controls: Implement a Web Application Firewall (WAF) or an access control list (ACL) to block public access to the /log directory. Ensure that the device management interface is not exposed to the public internet.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as documented in the Packet Storm Security reference.

Analyst recommendation

Given the ease with which sensitive information can be extracted, organizations using the affected SOUND4 products must treat this as a high-priority issue. Restricting network access to these systems is the most effective immediate mitigation while awaiting formal vendor patches. Administrators should prioritize the isolation of these devices from public-facing networks to prevent unauthorized data access.

Sources

Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.