SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive log files. Attackers can directly browse the /log directory to retrieve system and sensitive information without authentication.
The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| First_firmware | Sound4 | 2.15 (including) | 2.15 (including) |