CVE-2022-38168
Last modified
CVE-2022-38168 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackers to bypass the login page, access sensitive information, and reset user passwords via URL modification.. EPSS estimates a 1.07% chance of exploitation in the next 30 days.
Description
Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackers to bypass the login page, access sensitive information, and reset user passwords via URL modification.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Avaya | Scopia Pathfinder 10 Pts Firmware | 8.3.7.0.4 |
| Avaya | Scopia Pathfinder 20 Pts Firmware | 8.3.7.0.4 |
References
- https://medium.com/%40rob_nes/avaya-scopia-pathfinder-broken-access-control-ac792e995baeExploit, Third Party Advisory
- https://medium.com/%40rob_nes/avaya-scopia-pathfinder-broken-access-control-ac792e995baeExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-38168?
How severe is CVE-2022-38168?
How do I fix CVE-2022-38168?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-38162Reflected cross-site scripting (XSS) vulnerabilities in With…6.1
- CVE-2022-38163A Drag and Drop spoof vulnerability was discovered in F-Secu…3.5
- CVE-2022-38164A vulnerability affecting F-Secure SAFE browser for Android …6.5
- CVE-2022-38165Arbitrary file write in F-Secure Policy Manager through 2022…9.8
- CVE-2022-38166In F-Secure Endpoint Protection for Windows and macOS before…7.5
- CVE-2022-38167The Nintex Workflow plugin 5.2.2.30 for SharePoint allows XS…6.1
- CVE-2022-3817A vulnerability has been found in Axiomatic Bento4 and class…6.5
- CVE-2022-38170In Apache Airflow prior to 2.3.4, an insecure umask was conf…4.7
- CVE-2022-38171Xpdf prior to version 4.04 contains an integer overflow in t…7.8
- CVE-2022-38172ServiceNow through San Diego Patch 3 allows XSS via the name…6.1
- CVE-2022-38176An issue was discovered in YSoft SAFEQ 6 before 6.0.72. Inco…7.8
- CVE-2022-38177By spoofing the target resolver with responses that have a m…7.5
Are you affected by CVE-2022-38168?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
