VMware Avi Load Balancer
- >= 31.1.1, <= 31.2.2
- >= 30.1.1, <= 30.2.6
- >= 22.1.1, <= 22.1.7
A critical authentication bypass vulnerability has been identified in VMware Avi Load Balancer versions 31.1.1 through 31.2.2, 30.1.1 through 30.2.6, and 22.1.1 through 22.1.7. This vulnerability allows a malicious user with network access to bypass authentication and access the Avi Control plane. The issue has been evaluated with a CVSSv3 base score of 9.8, indicating its critical severity.
Exploitation of this vulnerability could lead to unauthorized access to the Avi Control plane, allowing attackers to manipulate load balancing configurations and potentially disrupt application availability.
Users can upgrade to VMware Avi Load Balancer versions 31.2.2-2p3, 30.2.7, or 32.1.2 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.