CVE-2022-50788
7.5SOUND4 Ltd. · IMPACT/FIRST/PULSE/Eco
SOUND4 products contain an information disclosure vulnerability allowing unauthenticated attackers to access sensitive log files via directory browsing.
Executive summary
An unauthenticated information disclosure vulnerability in multiple SOUND4 products allows remote attackers to access sensitive system logs, posing a significant risk to data confidentiality.
Vulnerability
This vulnerability is a directory listing flaw (CWE-548) that allows an unauthenticated, remote attacker to browse the /log directory. By accessing this endpoint, an attacker can retrieve sensitive system information without requiring any prior authentication or authorization.
Business impact
The exposure of system logs can lead to the leakage of sensitive configuration data, credentials, or operational details that facilitate further attacks. While the CVSS score of 7.5 indicates a high severity, the potential for an attacker to gain deep insight into the internal environment significantly increases the risk of a broader security compromise. Unauthorized access to these files may also result in regulatory non-compliance regarding data protection.
Remediation
Immediate Action: Contact the vendor immediately to obtain the appropriate security patches or firmware updates for your specific device model. If a patch is unavailable, restrict network access to the management interface of these devices to trusted management subnets only.
Proactive Monitoring: Monitor web access logs for unauthorized attempts to access directories or files within the /log path. Unusual spikes in traffic or requests for log files should be investigated as potential reconnaissance attempts.
Compensating Controls: Implement a Web Application Firewall (WAF) or an access control list (ACL) to block public access to the /log directory. Ensure that the device management interface is not exposed to the public internet.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in the Packet Storm Security reference.
Analyst recommendation
Given the ease with which sensitive information can be extracted, organizations using the affected SOUND4 products must treat this as a high-priority issue. Restricting network access to these systems is the most effective immediate mitigation while awaiting formal vendor patches. Administrators should prioritize the isolation of these devices from public-facing networks to prevent unauthorized data access.
Sources
Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.
- Zero Science Lab Disclosure (ZSL-2022-5732) Third-party advisory
- Packet Storm Security Exploit Details Exploit / PoC
- IBM X-Force Vulnerability Exchange Entry Vulnerability database entry
- SOUND4 Product Homepage
- VulnCheck Advisory: SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Information Disclosure via Log Directory Third-party advisory