Impact
The vulnerability in VMware Avi Load Balancer is a code injection flaw (CWE‑94) that allows a malicious, authenticated user with network access to supply input to the vulnerable component and execute arbitrary code on the appliance. Successful exploitation grants the attacker full control over the load balancer and any functions it provides, and the attacker operates with the privileges of the authenticated session used to deliver the payload.
Affected Systems
The vulnerability affects the VMware Avi Load Balancer product. Affected releases are 32.1.1 (fixed in 32.1.2), 31.1.1 through 31.2.2 (fixed in 31.2.2‑2p3), 30.1.1 through 30.2.6 (fixed in 30.2.7), and 22.1.1 through 22.1.7 (fixed in 30.2.7).
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, while the EPSS score of less than 1% shows a very low yet nonzero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is a malicious user who is already authenticated and has network access to the load balancer’s management interface; exploitation requires such access and is unlikely to occur via the public Internet. Given the high impact, organizations should treat the vulnerability as a critical risk and remediate promptly.
OpenCVE Enrichment