Impact
A malicious authenticated user with network access can leverage a privilege escalation flaw in VMware Avi Load Balancer to execute arbitrary code remotely. The vulnerability arises from improper access control checks, allowing an attacker who has authenticated credentials to attain higher privileges and run unauthorized commands. The impact is elevated to any user or host that can interact with the affected instance, potentially compromising confidentiality, integrity, and availability of the load balancer and connected services.
Affected Systems
VMware Avi Load Balancer versions 32.1.1, 31.1.1 through 31.2.2, 30.1.1 through 30.2.6, and 22.1.1 through 22.1.7 are affected. The fix versions are 32.1.2, 31.2.2-2p3, 30.2.7, and 30.2.7 for the older release stream.
Risk and Exploitability
The CVSS score of 7.1 reflects a high severity, but the EPSS score of less than 1% indicates a very low probability of current exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely observed in the wild. Attackers would need authenticated network access to the load balancer, which is likely limited to internal administrators or application users, thereby reducing the attack surface compared to non-authenticated vectors.
OpenCVE Enrichment