{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-22T16:11:30.776","vulnerabilities":[{"cve":{"id":"CVE-2025-25041","sourceIdentifier":"security-alert@hpe.com","published":"2025-04-01T17:15:44.967","lastModified":"2026-06-17T09:00:11.540","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow malicious users to overwrite arbitrary files as NT AUTHORITY\\SYSTEM (root). A successful exploit could allow the creation of a Denial-of-Service (DoS) condition affecting the Microsoft Windows Operating System. This vulnerability does not affect Linux and Android based clients."},{"lang":"es","value":"Una vulnerabilidad en el cliente HPE Aruba Networking Virtual Intranet Access (VIA) podría permitir a usuarios maliciosos sobrescribir archivos arbitrarios como NT AUTHORITY\\SYSTEM (root). Una explotación exitosa podría generar una condición de denegación de servicio (DoS) que afecte al sistema operativo Microsoft Windows. Esta vulnerabilidad no afecta a los clientes basados en Linux ni Android."}],"affected":[{"source":"security-alert@hpe.com","affectedData":[{"vendor":"Hewlett Packard Enterprise (HPE)","product":"Virtual Intranet Access (VIA)","defaultStatus":"affected","platforms":["Windows","Linux","MacOS","iOS"],"versions":[{"version":"4.0.0","lessThanOrEqual":"4.7.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-alert@hpe.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-01T19:51:40.983463Z","id":"CVE-2025-25041","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-732"}]}],"references":[{"url":"https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04841en_us&docLocale=en_US","source":"security-alert@hpe.com"}]}}]}