← back
CVE-2022-38168

CVE-2022-38168

CVSS 9.1 CRITICALEPSS 1.1%CWE-306
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.1EPSS 1.1%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
03 Nov 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackers to bypass the login page, access sensitive information, and reset user passwords via URL modification.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected products
n/a · n/a

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →