PoC Index

CVE-2022-38168

CRITICAL 9.1EPSS 1.1%

Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackers to bypass the login page, access sensitive information, and reset user passwords via URL modification.

CVSS v3.1
9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS v3.1
9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS
1.08% chance of exploitation in the next 30 days, 63th percentile
Published
2022-11-03
Updated
2025-05-02

Proof-of-concept exploits (1)

References

Related