Impact
The vulnerability in VMware Avi Load Balancer permits an attacker with network access to send specially crafted input to the Avi Control plane, leading to arbitrary code execution (CWE‑94). Successful exploitation provides the attacker full control over the load balancer system, compromising the confidentiality, integrity, and availability of all services managed by it.
Affected Systems
Affected products include VMware Avi Load Balancer. Versions 32.1.1 (fixed in 32.1.2), 31.1.1 through 31.2.2 (fixed in 31.2.2‑2p3), 30.1.1 through 30.2.6 (fixed in 30.2.7), and 22.1.1 through 22.1.7 (fixed in 30.2.7) are vulnerable.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability, while the EPSS score of less than 1% suggests a low probability of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog, meaning no known active exploitation has been reported, yet the potential impact warrants prompt action. Exploitation requires network‑level access to the Avi Control plane; isolating this plane from untrusted networks and applying the vendor patch are the most effective defenses.
OpenCVE Enrichment