VMware Avi Load Balancer
- 32.1.1
- 31.1.1 - 31.2.2
- 30.1.1 - 30.2.6
- 22.1.1 - 22.1.7
A remote code execution vulnerability has been identified in VMware Avi Load Balancer. This issue allows a malicious user with network access to the Avi Control Plane to execute code remotely. The vulnerability is present in versions 31.1.1 through 31.2.2, 30.1.1 through 30.2.6, and 22.1.1 through 22.1.7, with version 32.1.1 being the only exception. The vulnerability arises from flaws in the application's handling of network requests, which can be exploited to inject and execute arbitrary code on the server.
Exploitation of this vulnerability allows for remote code execution on the server where VMware Avi Load Balancer is running.
Users can upgrade to VMware Avi Load Balancer version 32.1.2, 31.2.2-2p3, or 30.2.7. For version 22.1.x, an upgrade to at least 30.2.7 is required.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.