CVE-2022-38168: Critical severity avaya scopia pathfinder vulnerability
UNSUPPPORTED WHEN ASSIGNED Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackers to bypass the login page, access sensitive information, and reset user passwords via URL modification.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability severity of CVE-2022-38168?
The vulnerability severity of CVE-2022-38168 is critical with a severity value of 9.1.
How does CVE-2022-38168 affect Avaya Scopia Pathfinder 10 PTS?
CVE-2022-38168 affects Avaya Scopia Pathfinder 10 PTS version 8.3.7.0.4, allowing remote unauthenticated attackers to bypass the login page, access sensitive information, and reset user passwords.
How does CVE-2022-38168 affect Avaya Scopia Pathfinder 20 PTS?
CVE-2022-38168 affects Avaya Scopia Pathfinder 20 PTS version 8.3.7.0.4, allowing remote unauthenticated attackers to bypass the login page, access sensitive information, and reset user passwords.
How can the vulnerability in Avaya Scopia Pathfinder be exploited?
The vulnerability in Avaya Scopia Pathfinder can be exploited by remote unauthenticated attackers through URL modification, bypassing the login page, accessing sensitive information, and resetting user passwords.
Is Avaya Scopia Pathfinder 10 PTS vulnerable to CVE-2022-38168?
Avaya Scopia Pathfinder 10 PTS is vulnerable to CVE-2022-38168, specifically in version 8.3.7.0.4.
Is Avaya Scopia Pathfinder 20 PTS vulnerable to CVE-2022-38168?
Avaya Scopia Pathfinder 20 PTS is vulnerable to CVE-2022-38168, specifically in version 8.3.7.0.4.