High severity7.8NVD Advisory· Published Aug 15, 2023· Updated Jun 17, 2026
CVE-2023-38401
CVE-2023-38401
Description
A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow local users to elevate privileges. Successful exploitation could allow execution of arbitrary code with NT AUTHORITY\SYSTEM privileges on the operating system.
Affected products
4- cpe:2.3:a:hp:aruba_virtual_intranet_access:*:*:*:*:*:*:*:*Range: <4.5.0
- Hewlett Packard Enterprise (HPE)/HPE Aruba Networking Virtual Intranet Access (VIA)v5Range: HPE Aruba Networking Virtual Intranet Access (VIA) client for Microsoft Windows
Patches
Vulnerability mechanics
References
1- www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-011.txtnvdVendor Advisory
News mentions
0No linked articles in our index yet.