SOUND4 Impact/First/Pulse/Eco ICMP Flood Attack Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in SOUND4 Impact, First, Pulse, and Eco versions 2.x. This vulnerability allows unauthenticated attackers to send ICMP signals to arbitrary hosts, potentially leading to network flooding attacks. The issue arises from the application's network command scripts, which can be exploited using the ping, traceroute, and DNS command functionalities. Affected products include SOUND4 Impact/Pulse/First (Version 2: 1.1/2.15), Impact/Pulse Eco 1.16, BigVoice4 1.2, BigVoice2 1.30, Stream 1.1/2.4.29, and WM2 (Kantar Media) 1.11.

Impact

Exploitation of this vulnerability can cause a denial-of-service condition on the targeted external hosts by flooding them with ICMP traffic.

Reproduction

The vulnerability can be reproduced by sending POST requests to the vulnerable application's ping.php, traceroute.php, or dns.php scripts. These requests can include parameters that specify the target host for the ICMP flood attack.

Added: Dec 30, 2025, 11:52 PM
Updated: Dec 30, 2025, 11:52 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
1.8
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.