关键漏洞信息 漏洞名称: SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Information Disclosure via Log Directory 风险等级: MEDIUM 发布时间: December 30, 2025 漏洞详情: - CVE ID: CVE-2022-50788 - CWE ID: CWE-548 Exposure of Information Through Directory Listing - CVSS: 6.9 - CVSS V4 Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L /VI:N/VA:N/SC:N/SI:N/SA:N 受影响版本: - Impact/Pulse/First Version 2: 1.1/2.15 - Impact/Pulse/Eco 1.16 - BigVoice4 1.2 - BigVoice2 1.30 - MasterStream 1.1/2.4.29 - VM2 1.11 参考资料: - Zero Science Lab Disclosure (ZSL-2022-5732) - Packet Storm Security Exploit Details - IBM X-Force Vulnerability Exchange Entry - SOUND4 Product Homepage 漏洞描述: This vulnerability allows unauthenticated attackers to access sensitive log files directly by browsing the directory, which can reveal system and sensitive information. 发现者: LiquidWorm as Gjoko Krstic of Zero Science Lab