SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access hidden system resources. Attackers can exploit the vulnerability by manipulating user-supplied input to execute privileged functionalities without proper authentication.
The vulnerability (CWE-639) consists in the application not properly verifying user permissions when accessing internal system objects. An attacker can manipulate user-supplied data (e.g., request parameters) in such a way as to directly reference protected resources or functions. The lack of proper access control on the server side enables the execution of privileged operations without valid authentication.
A remote unauthenticated attacker can gain unauthorized access to hidden system resources and execute privileged functions on the device, leading to violations of system confidentiality, integrity, and availability.
Apply patches available from the manufacturer according to the references. As a temporary measure, it is recommended to restrict network access to SOUND4 device management interfaces through a firewall or network segmentation, so they are accessible only from trusted hosts.
SOUND4 IMPACT, SOUND4 FIRST, SOUND4 PULSE, SOUND4 Pulse Eco, SOUND4 Big Voice2, SOUND4 Big Voice4 — all in firmware version v2.x
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSound4 Big Voice2
HWSound4all versionsSound4 Big Voice2 Firmware
OSSound41.30Sound4 Big Voice4
HWSound4all versionsSound4 Big Voice4 Firmware
OSSound41.2Sound4 First
HWSound41.02.0Sound4 First Firmware
OSSound41.692.15Sound4 Impact
HWSound41.02.0Sound4 Impact Eco
HWSound4all versionsSound4 Impact Eco Firmware
OSSound41.16Sound4 Impact Firmware
OSSound41.692.15Sound4 Pulse
HWSound41.02.0Sound4 Pulse Eco
HWSound4all versionsSound4 Pulse Eco Firmware
OSSound41.16Sound4 Pulse Firmware
OSSound41.692.15Sound4 Stream Extension
APPSound42.4.29Sound4 Wm2
HWSound4all versionsSound4 Wm2 Firmware
OSSound41.11
Related vulnerabilities
RCE i path traversal w firmware upload SOUND4 IMPACT/FIRST/PULSE/Eco
Command injection w parametrze username — SOUND4 IMPACT/FIRST/PULSE/Eco
Zakodowane na stałe dane logowania w urządzeniach SOUND4 IMPACT/FIRST/PULSE/Eco
SQL Injection w mechanizmie logowania SOUND4 IMPACT/FIRST/PULSE/Eco
Nieuwierzytelniony OS command injection w SOUND4 IMPACT/FIRST/PULSE/Eco v2.x