CVE-2022-50788
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive log files. Attackers can directly browse the /log directory to retrieve system and sensitive information without authentication.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 7.5
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.51%
- CWE
- CWE-548
- Published
- 2025-12-30
- Last modified
- 2026-03-13
Affected products
- SOUND4 Ltd. Impact/Pulse/First
- SOUND4 Ltd. Impact/Pulse Eco
- SOUND4 Ltd. BigVoice4
- SOUND4 Ltd. BigVoice2
- SOUND4 Ltd. Stream
- Kantar Media WM2
Weakness type
Related vulnerabilities
- CVE-2026-19987 — SourceCodester Best Employee Management System Profile exposure of information through directory listing
- CVE-2026-50233 — Lyrion Music Server 9.2.0 Arbitrary Directory Listing
- CVE-2025-32750 — Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory...
- CVE-2026-41933 — Vvveb < 1.0.8.3 Directory Listing Information Disclosure
- CVE-2026-22860 — Rack has a Directory Traversal via Rack:Directory
- CVE-2023-38265 — Improper Access Control and Exposure of Information Through Directory Listing vulnerabilities affect IBM Cloud Pak System[, ]
- CVE-2020-36921 — RED-V Super Digital Signage System 5.1.1 Log Information Disclosure Vulnerability
- CVE-2021-47718 — OpenBMCS Directory Listing Information Disclosure