9.1
CVSSv3

CVE-2022-38168

Published: 03/11/2022 Updated: 11/04/2024
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated malicious users to bypass the login page, access sensitive information, and reset user passwords via URL modification.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

avaya scopia_pathfinder_10_pts_firmware 8.3.7.0.4

avaya scopia_pathfinder_20_pts_firmware 8.3.7.0.4