CVE-2022-38168

** UNSUPPPORTED WHEN ASSIGNED **Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackers to bypass the login page, access sensitive information, and reset user passwords via URL modification.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:avaya:scopia_pathfinder_10_pts_firmware:8.3.7.0.4:*:*:*:*:*:*:*
cpe:2.3:h:avaya:scopia_pathfinder_10_pts:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:avaya:scopia_pathfinder_20_pts_firmware:8.3.7.0.4:*:*:*:*:*:*:*
cpe:2.3:h:avaya:scopia_pathfinder_20_pts:-:*:*:*:*:*:*:*

Information

Published : 2022-11-03 14:15

Updated : 2022-11-08 08:06


NVD link : CVE-2022-38168

Mitre link : CVE-2022-38168


JSON object : View

CWE
CWE-306

Missing Authentication for Critical Function

Advertisement

dedicated server usa

Products Affected

avaya

  • scopia_pathfinder_10_pts_firmware
  • scopia_pathfinder_10_pts
  • scopia_pathfinder_20_pts_firmware
  • scopia_pathfinder_20_pts