Impact
VMware Avi Load Balancer is vulnerable to a local privilege escalation that allows a malicious user with local access to execute code as root. The flaw enables the attacker to elevate privileges and potentially take full control of the host, compromising confidentiality, integrity, and availability of the services it protects.
Affected Systems
The vulnerability affects VMware Avi Load Balancer versions 32.1.1 (fixed in 32.1.2), 31.1.1 through 31.2.2 (fixed in 31.2.2‑2p3), 30.1.1 through 30.2.6 (fixed in 30.2.7), and 22.1.1 through 22.1.7 (also fixed in 30.2.7).
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, but the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector requires local access, such as a local user account or a compromised local service. Once the privilege escalation is achieved, an attacker could run arbitrary code, modify configurations, or fully compromise the managed system.
OpenCVE Enrichment