Database/Control plane, storage & DevOps
VMware Avi Load Balancer: authenticated privilege escalation leading to remote code execution
Impact
An authenticated Avi user can escalate privilege to the point of executing code remotely on the Controller. The practical consequence is the same as the other Controller flaws in this advisory: whoever holds a modest Avi login ends up owning the device that fronts every published service. Where inference endpoints for several tenants share one Avi instance, that is a tenancy boundary failure, and the Controller also stores the certificates and pool configuration for those endpoints. No further technical detail is published in the record.
Who can reach it
Authenticated network access to the Avi Controller. No pre-auth path is described.
What to do
Upgrade the Controller to 32.1.2, 31.2.2-2p3, or 30.2.7 for your train (22.1.x moves to 30.2.7) - a Controller software upgrade and restart. This is the same fix that closes the other three issues published alongside it.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.