VMware Avi Load Balancer
- 32.1.1
- 31.1.1 - 31.2.2
- 30.1.1 - 30.2.6
- 22.1.1 - 22.1.7
An authorization bypass vulnerability has been identified in VMware Avi Load Balancer. This vulnerability allows a malicious actor on the network to access a limited subset of the Avi Control Plane without proper authorization. The issue is present in VMware Avi Load Balancer versions 31.1.1 through 31.2.2, 30.1.1 through 30.2.6, and 22.1.1 through 22.1.7, with version 32.1.1 being the only version currently available that is not vulnerable.
Exploitation of this vulnerability could lead to unauthorized access to certain areas of the Avi Control Plane, potentially allowing for further actions or exploits within that environment.
Users can upgrade to VMware Avi Load Balancer version 32.1.2, 31.2.2-2p3, or 30.2.7. For those on version 22.1.x, an upgrade to at least 30.2.7 is required.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.