CVE-2022-50790
Estado: ModificadaMedia (6.9)—
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated vulnerability that allows remote attackers to access live radio stream information through webplay or ffmpeg scripts. Attackers can exploit the vulnerability by calling specific web scripts to disclose radio stream details without requiring authentication.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 6.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.79%
- Percentil entre todas las CVEs puntuadas: 55
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (9)
CWE
- CWE-306
Referencias
- https://exchange.xforce.ibmcloud.com/vulnerabilities/247923
- https://packetstormsecurity.com/files/170261/SOUND4-IMPACT-FIRST-PULSE-Eco-2.x-Radio-Steam-Disclosure.html
- https://www.sound4.com/
- https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-unauthenticated-radio-stream-disclosure
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5734.php
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-50790",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-50790",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-03-04T19:27:34.733369Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "disclosure@vulncheck.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
},
{
"type": "Secondary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "disclosure@vulncheck.com",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 6.9,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "disclosure@vulncheck.com",
"affectedData": [
{
"vendor": "SOUND4 Ltd.",
"product": "Impact/Pulse/First",
"versions": [
{
"status": "affected",
"version": "Version 2: 1.1/2.15"
}
]
},
{
"vendor": "SOUND4 Ltd.",
"product": "Impact/Pulse Eco",
"versions": [
{
"status": "affected",
"version": "1.16"
}
]
},
{
"vendor": "SOUND4 Ltd.",
"product": "BigVoice4",
"versions": [
{
"status": "affected",
"version": "1.2"
}
]
},
{
"vendor": "SOUND4 Ltd.",
"product": "BigVoice2",
"versions": [
{
"status": "affected",
"version": "1.30"
}
]
},
{
"vendor": "SOUND4 Ltd.",
"product": "Stream",
"versions": [
{
"status": "affected",
"version": "1.1/2.4.29"
}
]
},
{
"vendor": "Kantar Media",
"product": "WM2",
"versions": [
{
"status": "affected",
"version": "1.11"
}
]
}
]
}
],
"published": "2025-12-30T23:15:45.723",
"references": [
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/247923",
"tags": [
"Third Party Advisory"
],
"source": "disclosure@vulncheck.com"
},
{
"url": "https://packetstormsecurity.com/files/170261/SOUND4-IMPACT-FIRST-PULSE-Eco-2.x-Radio-Steam-Disclosure.html",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "disclosure@vulncheck.com"
},
{
"url": "https://www.sound4.com/",
"tags": [
"Product"
],
"source": "disclosure@vulncheck.com"
},
{
"url": "https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-unauthenticated-radio-stream-disclosure",
"tags": [
"Third Party Advisory"
],
"source": "disclosure@vulncheck.com"
},
{
"url": "https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5734.php",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "disclosure@vulncheck.com"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "disclosure@vulncheck.com",
"description": [
{
"lang": "en",
"value": "CWE-306"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated vulnerability that allows remote attackers to access live radio stream information through webplay or ffmpeg scripts. Attackers can exploit the vulnerability by calling specific web scripts to disclose radio stream details without requiring authentication."
},
{
"lang": "es",
"value": "Las versiones 2.x e inferiores de SOUND4 IMPACT/FIRST/PULSE/Eco contienen una vulnerabilidad no autenticada que permite a atacantes remotos acceder a información de transmisión de radio en vivo a través de scripts webplay o ffmpeg. Los atacantes pueden explotar la vulnerabilidad al llamar a scripts web específicos para divulgar detalles de la transmisión de radio sin requerir autenticación."
}
],
"lastModified": "2026-06-17T05:24:11.260",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:sound4:impact_firmware:2.15:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "33C347FE-DA7B-4137-87B8-E6A8AF4D307F"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:sound4:impact:2.0:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "0A735654-A166-4B56-BF4D-F165B7E11043"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:sound4:impact_firmware:1.69:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5C4CF02A-8CF1-46FF-9EC0-FF779D60B6EA"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:sound4:impact:1.0:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "EC9BD81B-573A-4DA7-AC47-6C8AF1B6B18F"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:sound4:pulse_firmware:2.15:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "18E34118-F11B-4BF2-BE23-7DAE0A6790FB"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:sound4:pulse:2.0:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "C46BF88C-955C-4F9E-B782-1EADA068F19D"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:sound4:pulse_firmware:1.69:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E0699DEA-9CDA-4BB4-8FA3-6A6FADE1A61E"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:sound4:pulse:1.0:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "051868AE-E364-4CB3-B927-42B4E0C19D01"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:sound4:first_firmware:2.15:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FBDECDEC-C5A2-4B0D-B3E0-58CCCC804BCF"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:sound4:first:2.0:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4EF10967-A7DC-4DF0-94BE-935FFC1888D6"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:sound4:first_firmware:1.69:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "713CC97E-CC0A-41B8-B8CA-EAD8F774F77C"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:sound4:first:1.0:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "C4034A51-85E1-44E7-973B-7BFFFB083832"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:sound4:impact_eco_firmware:1.16:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5ED99BE5-4598-4D5C-B0F0-3BE6E5B05C10"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:sound4:impact_eco:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B4B0A611-C50E-4397-ACDF-8D090D4AFC88"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:sound4:pulse_eco_firmware:1.16:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9A3C132F-ACCE-4618-8EC2-31624571F0BF"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:sound4:pulse_eco:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "71E155FD-162E-4EA9-9BD9-89384B3AD175"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:sound4:big_voice4_firmware:1.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DFF4C955-E4AF-4A3A-89F9-481CE5DB7BF1"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:sound4:big_voice4:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "404A1397-CD88-4CB5-99B9-B84F3359E13F"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:sound4:big_voice2_firmware:1.30:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "45230C2E-D043-45F5-869F-FEB0A3AEB5DE"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:sound4:big_voice2:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "8C68C1DC-EC1C-445B-B78C-6E4B64BB5DB0"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:sound4:wm2_firmware:1.11:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "05D5318D-BD08-4D8E-9D94-4D0FD0C0023E"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:sound4:wm2:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "ED8E14DD-2C04-4080-AAE9-6D770436AC6C"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sound4:stream_extension:2.4.29:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DFFD1447-69A1-4FA0-B285-6F16D9113558"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "disclosure@vulncheck.com"
}