CVE-2022-38168

CRITICAL

Avaya Scopia Pathfinder <8.3.7.0.4 - Auth Bypass

Title source: llm
STIX 2.1

Description

Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackers to bypass the login page, access sensitive information, and reset user passwords via URL modification.

References (1)

Core 1

Scores

CVSS v3 9.1
EPSS 0.0107
EPSS Percentile 60.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-306
Status published
Products (2)
avaya/scopia_pathfinder_10_pts_firmware 8.3.7.0.4
avaya/scopia_pathfinder_20_pts_firmware 8.3.7.0.4
Published Nov 03, 2022
Tracked Since Feb 18, 2026