Vulnerability Name: | CVE-2022-38168 (CCN-239726) | ||||||||||||
Assigned: | 2022-11-02 | ||||||||||||
Published: | 2022-11-02 | ||||||||||||
Updated: | 2022-11-08 | ||||||||||||
Summary: | ** UNSUPPPORTED WHEN ASSIGNED **Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackers to bypass the login page, access sensitive information, and reset user passwords via URL modification. | ||||||||||||
CVSS v3 Severity: | 9.1 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N) 8.8 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:H/RL:U/RC:R)
8.5 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:H/RL:U/RC:R)
| ||||||||||||
CVSS v2 Severity: | 9.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C)
| ||||||||||||
Vulnerability Type: | CWE-306 | ||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2022-38168 Source: XF Type: UNKNOWN avaya-scopia-cve202238168-sec-bypass(239726) Source: CCN Type: Medium Web site CVE-202238168: Avaya Scopia Pathfinder Broken Access Control Source: CCN Type: Avaya Web site Scopia | ||||||||||||
BACK |