File Overwrite Vulnerability in HPE Aruba Networking VIA Client
CVE-2025-25041
5.5MEDIUM
Key Information:
- Vendor
- HP (HP)
- Status
- Virtual Intranet Access (via)
- Vendor
- CVE Published:
- 1 April 2025
Summary
A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client permits malicious users to overwrite arbitrary files, potentially gaining access as NT AUTHORITY\SYSTEM on the Microsoft Windows Operating System. Successful exploitation of this vulnerability may lead to a Denial-of-Service (DoS) condition. Notably, this issue is exclusive to Windows clients and does not impact Linux and Android platforms. Organizations using the affected VIA client should implement security measures to mitigate potential risks.
Affected Version(s)
Virtual Intranet Access (VIA) Windows 4.0.0 <= 4.7.0
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Gee-netics