Impact
VMware Avi Load Balancer contains an authorization bypass vulnerability (CWE-863) that allows a malicious actor on the network to access a limited subset of the Avi Control Plane without proper authorization.
Affected Systems
The vulnerability affects VMware Avi Load Balancer. Affected versions are 32.1.1 (fixed in 32.1.2), 31.1.1 through 31.2.2 (fixed in 31.2.2‑2p3), 30.1.1 through 30.2.6 (fixed in 30.2.7), and 22.1.1 through 22.1.7 (fixed in 30.2.7).
Risk and Exploitability
The CVSS base score of 8.3 indicates a high potential impact if the vulnerability is exploited. The EPSS score is less than 1%, suggesting a low probability of active exploitation in the wild at present. The vulnerability is not listed in the CISA KEV catalog, so no documented exploit campaigns are known. The likely attack vector involves network traffic directed at Avi Control Plane endpoints, enabling unauthorized access to a constrained set of configuration interfaces without proper checks.
OpenCVE Enrichment