PT-2025-54240 · Pulse+3 · Pulse+3

Published

2025-12-30

·

Updated

2025-12-31

·

CVE-2022-50792

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below
Description The software contains an unauthenticated file disclosure issue that allows remote attackers to access sensitive system files. Attackers can exploit the issue by manipulating the file GET parameter to disclose arbitrary files on the affected device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-50792

Affected Products

Eco
First
Pulse
Sound4 Impact