First published: Tue Aug 15 2023(Updated: )
A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow malicious users to overwrite arbitrary files as NT AUTHORITY\SYSTEM. A successful exploit could allow these malicious users to create a Denial-of-Service (DoS) condition affecting the Microsoft Windows operating System boot process.
Credit: security-alert@hpe.com security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hp Aruba Virtual Intranet Access | <4.5.0 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38402 is a vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client that could allow malicious users to overwrite arbitrary files as NT AUTHORITY\SYSTEM.
CVE-2023-38402 could create a Denial-of-Service (DoS) condition affecting Microsoft Windows.
CVE-2023-38402 has a severity level of 7.1 (high).
The HPE Aruba Networking Virtual Intranet Access (VIA) client version up to and exclusive of 4.5.0 is affected.
To fix CVE-2023-38402, update your HPE Aruba Networking Virtual Intranet Access (VIA) client to a version beyond 4.5.0.