Authenticated SQL Injection Vulnerability in VMware Avi Load Balancer
CVE-2025-41233

6.8MEDIUM

Key Information:

Vendor

Vmware

Vendor
CVE Published:
12 June 2025

What is CVE-2025-41233?

VMware Avi Load Balancer has a vulnerability that allows an authenticated attacker to perform blind SQL injection due to insufficient input validation. This flaw affects multiple versions, including 30.1.1, 30.1.2, 30.2.1, and 30.2.2. An attacker with network access can exploit this vulnerability to execute specially crafted SQL queries, resulting in unauthorized access to the database. It is crucial for users to apply the recommended patches as per VMware's response matrix to mitigate this risk.

Affected Version(s)

Avi Load Balancer 30.1.1

Avi Load Balancer 30.1.1

Avi Load Balancer 30.1.2

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-41233 : Authenticated SQL Injection Vulnerability in VMware Avi Load Balancer