CVE-2023-38402: HP Aruba Virtual Intranet Access

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow malicious users to overwrite arbitrary files as NT AUTHORITY\SYSTEM. A successful exploit could allow these malicious users to create a Denial-of-Service (DoS) condition affecting the Microsoft Windows operating System boot process.

Affected products

  • HP Aruba Virtual Intranet Access: before 4.5.0 (fixed in 4.5.0)

Published 2023-08-15. Last modified 2026-06-17.