CVE-2023-38402

A vulnerability in the HPE Aruba Networking Virtual IntranetAccess (VIA) client could allow malicious users to overwritearbitrary files as NT AUTHORITY\SYSTEM. A successfulexploit could allow these malicious users to create aDenial-of-Service (DoS) condition affecting the MicrosoftWindows operating System boot process.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.1 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
hpeCNA
7.1 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 35%
VendorProductVersion
hparuba_virtual_intranet_access
𝑥
< 4.5.0
𝑥
= Vulnerable software versions