AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-38168

CRITICAL · CVSS 9.1 EPSS 1.07%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-11-03 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2022-38168
Severity
CRITICAL
CVSS
9.1
EPSS
1.07%

Original NVD Description

Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackers to bypass the login page, access sensitive information, and reset user passwords via URL modification.