CVE-2023-53965
8.6
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: disclosure@vulncheck.com (Secondary)
Description
SOUND4 Server Service 4.1.102 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary path by inserting malicious code in the system root path that could execute with LocalSystem privileges during service startup.
Affected (15)
Products: Sound4: Playout Ula8 Firmware, Stream X8 Firmware, Stream X4 Firmware, Stream X2 Firmware, Wm2 Firmware, Ip Connect Firmware, Voice Ula8 Firmware, Voice Ula4 Firmware, Voice Ula2 Firmware, Big Voice Firmware, Pulse Eco Firmware, Impact Eco Firmware, First Firmware, Pulse Firmware, Impact Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.1.102 |
| Running on/with | Platform Versions |
|---|---|
Sound4 Playout Ula8 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.1.102 |
| Running on/with | Platform Versions |
|---|---|
Sound4 Stream X8 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.1.102 |
| Running on/with | Platform Versions |
|---|---|
Sound4 Stream X4 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.1.102 |
| Running on/with | Platform Versions |
|---|---|
Sound4 Stream X2 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.1.102 |
| Running on/with | Platform Versions |
|---|---|
Sound4 Wm2 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.1.102 |
| Running on/with | Platform Versions |
|---|---|
Sound4 Ip Connect | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.1.102 |
| Running on/with | Platform Versions |
|---|---|
Sound4 Voice Ula8 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.1.102 |
| Running on/with | Platform Versions |
|---|---|
Sound4 Voice Ula4 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.1.102 |
| Running on/with | Platform Versions |
|---|---|
Sound4 Voice Ula2 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.1.102 |
| Running on/with | Platform Versions |
|---|---|
Sound4 Big Voice | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.1.102 |
| Running on/with | Platform Versions |
|---|---|
Sound4 Pulse Eco | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.1.102 |
| Running on/with | Platform Versions |
|---|---|
Sound4 Impact Eco | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.1.102 |
| Running on/with | Platform Versions |
|---|---|
Sound4 First | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.1.102 |
| Running on/with | Platform Versions |
|---|---|
Sound4 Pulse | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.1.102 |
| Running on/with | Platform Versions |
|---|---|
Sound4 Impact | All versions |
References (5)
Source: disclosure@vulncheck.com
Product
Source: disclosure@vulncheck.com
ExploitThird Party Advisory
Source: disclosure@vulncheck.com
Third Party Advisory
Source: disclosure@vulncheck.com
ExploitThird Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
ExploitThird Party Advisory
Timeline
No history available yet.