Vulnerability Description
Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackers to bypass the login page, access sensitive information, and reset user passwords via URL modification.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Avaya | Scopia Pathfinder 10 Pts Firmware | 8.3.7.0.4 |
| Avaya | Scopia Pathfinder 10 Pts | - |
| Avaya | Scopia Pathfinder 20 Pts Firmware | 8.3.7.0.4 |
| Avaya | Scopia Pathfinder 20 Pts | - |
Related Weaknesses (CWE)
References
- https://medium.com/%40rob_nes/avaya-scopia-pathfinder-broken-access-control-ac79ExploitThird Party Advisory
- https://medium.com/%40rob_nes/avaya-scopia-pathfinder-broken-access-control-ac79ExploitThird Party Advisory
FAQ
What is CVE-2022-38168?
CVE-2022-38168 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackers to bypass the login page, access sensitive information, ...
How severe is CVE-2022-38168?
CVE-2022-38168 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-38168?
Check the references section above for vendor advisories and patch information. Affected products include: Avaya Scopia Pathfinder 10 Pts Firmware, Avaya Scopia Pathfinder 10 Pts, Avaya Scopia Pathfinder 20 Pts Firmware, Avaya Scopia Pathfinder 20 Pts.