CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-22217: Avi Load Balancer contains an unauthenticated blind SQL Injection vulnerability which was privately reported to VMware. Patches are available to...

8.6 CVSS

Description

Avi Load Balancer contains an unauthenticated blind SQL Injection vulnerability which was privately reported to VMware. Patches are available to remediate this vulnerability in affected VMware products. 

A malicious user with network access may be able to use specially crafted SQL queries to gain database access.

Classification

CVE ID: CVE-2025-22217

CVSS Base Severity: HIGH

CVSS Base Score: 8.6

Affected Products

Vendor: N/A

Product: VMware AVI Load Balancer

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.77% (scored less or equal to compared to others)

EPSS Date: 2025-02-27 (when was this score calculated)

References

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25346

Timeline