CRITICAL🇵🇱 Wersja polska

CVE-2022-38168

CVSS 9.1v3.1pub. 2022-11-03upd. 2025-05-02

Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackers to bypass the login page, access sensitive information, and reset user passwords via URL modification.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Avaya Scopia Pathfinder 10 Pts

    HW
    Avaya
    all versions
  • Avaya Scopia Pathfinder 10 Pts Firmware

    OS
    Avaya
    8.3.7.0.4
  • Avaya Scopia Pathfinder 20 Pts

    HW
    Avaya
    all versions
  • Avaya Scopia Pathfinder 20 Pts Firmware

    OS
    Avaya
    8.3.7.0.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2025-1041CRITICAL9.9PL ✓same vendor

Zdalne wykonanie poleceń w Avaya Call Management System (CWE-20)

CVE-2024-4197CRITICAL9.9PL ✓same vendor

Unrestricted file upload umożliwiający RCE w Avaya IP Office (One-X)

CVE-2024-4196CRITICAL10.0PL ✓same vendor

RCE poprzez improper input validation w Avaya IP Office (Web Control)

CVE-2019-7003CRITICAL10.0PL ✓same vendor

SQL Injection w Avaya Control Manager — nieautoryzowany dostęp do danych

CVE-2019-7001CRITICAL9.9PL ✓same vendor

SQL injection w Avaya IP Office Contact Center WebUI