Impact
Avi Load Balancer suffers an authentication bypass that lets an attacker with network access reach the control plane without valid credentials. The vulnerability is a classic credential validation flaw (CWE‑287). An adversary who succeeds can read and modify configuration, disrupt traffic, or insert malicious policies, effectively gaining full control over load‑balancing services and potentially exposing protected data or routing traffic to malicious destinations.
Affected Systems
The vulnerability affects VMware’s Avi Load Balancer product across multiple major releases: versions 31.1.1 through 31.2.2 (fixed in 31.2.2‑2p3), 30.1.1 through 30.2.6 (fixed in 30.2.7), and 22.1.1 through 22.1.7 (also fixed in 30.2.7). Any deployment running an affected version without the corresponding patch is vulnerable.
Risk and Exploitability
The CVSS score of 9.8 categorises this as critically severe. While the EPSS score of less than 1% suggests a modest exploitation probability, the lack of an existing CISA KEV listing does not diminish potential impact. The likely attack vector is through network access to the Avi control plane interface, requiring no special user privileges beyond network connectivity. Once accessed, an attacker can perform privileged configuration and potentially compromise the availability or integrity of the serving infrastructure.
OpenCVE Enrichment