CVE-2023-53955
CRITICALSOUND4 IMPACT/FIRST/PULSE/Eco v2.x - Auth Bypass
Title source: llmDescription
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access hidden system resources. Attackers can exploit the vulnerability by manipulating user-supplied input to execute privileged functionalities without proper authentication.
Exploits (1)
References (4)
Scores
CVSS v3
9.8
EPSS
0.0066
EPSS Percentile
71.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-639
Status
published
Products (12)
sound4/big_voice2_firmware
1.30
sound4/big_voice4_firmware
1.2
sound4/first_firmware
2.15
sound4/first_firmware
1.69
sound4/impact_eco_firmware
1.16
sound4/impact_firmware
2.15
sound4/impact_firmware
1.69
sound4/pulse_eco_firmware
1.16
sound4/pulse_firmware
2.15
sound4/pulse_firmware
1.69
... and 2 more
Published
Dec 22, 2025
Tracked Since
Feb 18, 2026