CVE-2022-38168
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: NVD
Description
Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackers to bypass the login page, access sensitive information, and reset user passwords via URL modification.
Affected (2)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.3.7.0.4 |
| Running on/with | Platform Versions |
|---|---|
Avaya Scopia Pathfinder 10 Pts | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.3.7.0.4 |
| Running on/with | Platform Versions |
|---|---|
Avaya Scopia Pathfinder 20 Pts | All versions |
References (2)
Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Timeline
No history available yet.