High-Severity SQL Injection Vulnerability in VMware Avi Load Balancer
2025-01-29
Learn about the critical importance of timely patch management to protect against high-severity vulnerabilities in key infrastructure components like VMware Avi Load Balancer.
Broadcom has identified a high-severity SQL injection vulnerability in VMware Avi Load Balancer that allows unauthorized users with network access to execute specially crafted SQL queries to gain database access. Affected versions include 30.1.1, 30.1.2, 30.2.1, and 30.2.2, and users are advised to update to the latest patched versions as there are no workarounds available.
Patch Management, Web App/Website Vulnerability
VMware Avi Load Balancer, SQL Injection, CVE-2025-22217, Patch Management, Broadcom
VMware Avi Load Balancer
Broadcom has issued a warning about a critical security vulnerability in the VMware Avi Load Balancer. This flaw, identified as CVE-2025-22217, is a high-severity unauthenticated blind SQL injection vulnerability with a CVSS score of 8.6. It poses a significant risk as it allows malicious actors with network access to execute specially crafted SQL queries, potentially gaining unauthorized access to the database. The vulnerability affects the following versions of VMware Avi Load Balancer:
- Version 30.1.1
- Version 30.1.2
- Version 30.2.1
- Version 30.2.2 Unfortunately, there are no workarounds to mitigate this vulnerability. Therefore, it is crucial for users to update their systems to the latest patched versions to ensure protection against potential exploitation. The fixed versions are:
- Version 30.1.2-2p2
- Version 30.2.1-2p5
- Version 30.2.2-2p2 This incident underscores the importance of timely patch management in maintaining the security of critical infrastructure components. Organizations are encouraged to prioritize updates and regularly review their security posture to defend against emerging threats and vulnerabilities.High-Severity Vulnerability in VMware Avi Load Balancer
Affected Versions
No Workarounds Available
Importance of Patch Management
https://thehackernews.com/2025/01/broadcom-warns-of-high-severity-sql.html?m=1