Impact
VMware Avi Load Balancer is vulnerable to directory traversal due to insufficient validation of file paths. An attacker who has valid network credentials can supply crafted path components that cause the system to resolve to files outside the intended directory. This can lead to reading sensitive configuration files or other data that should be restricted, potentially exposing secrets, service accounts or system details. The vulnerability is a high‑severity flaw, reflected in a CVSS score of 8.8, but it does not provide arbitrary code execution or privilege escalation by itself. The primary confidentiality impact is data disclosure that might assist in further attacks.
Affected Systems
The affected product is VMware Avi Load Balancer. Versions vulnerable include 32.1.1 (fixed in 32.1.2), 31.1.1 through 31.2.2 (fixed in 31.2.2‑2p3), 30.1.1 through 30.2.6 (fixed in 30.2.7) and 22.1.1 through 22.1.7 (fixed in 30.2.7).
Risk and Exploitability
The flaw carries a CVSS score of 8.8, indicating a high level of risk. The EPSS score is below 1 %, suggesting that, although the vulnerability is severe, the probability of exploitation is currently low. It is not listed in the CISA KEV catalog. The exploit requires an authenticated network user; an attacker with valid credentials could request a file using a path that includes traversal sequences. Holding appropriate privileges, the attacker might view files outside the trusted scope, which can lead to information leaks and additional compromise opportunities.
OpenCVE Enrichment