CVE-2023-53965: SOUND4 Big Voice Firmware
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
SOUND4 Server Service 4.1.102 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary path by inserting malicious code in the system root path that could execute with LocalSystem privileges during service startup.
Affected products
- SOUND4 Big Voice Firmware: version 4.1.102 only
- SOUND4 First Firmware: version 4.1.102 only
- SOUND4 Impact Eco Firmware: version 4.1.102 only
- SOUND4 Impact Firmware: version 4.1.102 only
- SOUND4 IP Connect Firmware: version 4.1.102 only
- SOUND4 Playout ULA8 Firmware: version 4.1.102 only
- SOUND4 Pulse Eco Firmware: version 4.1.102 only
- SOUND4 Pulse Firmware: version 4.1.102 only
- SOUND4 Stream x2 Firmware: version 4.1.102 only
- SOUND4 Stream x4 Firmware: version 4.1.102 only
- SOUND4 Stream x8 Firmware: version 4.1.102 only
- SOUND4 Voice ULA2 Firmware: version 4.1.102 only
- SOUND4 Voice ULA4 Firmware: version 4.1.102 only
- SOUND4 Voice ULA8 Firmware: version 4.1.102 only
- SOUND4 WM2 Firmware: version 4.1.102 only
Published 2025-12-22. Last modified 2026-06-17.