VMware Security Update – 29 January 2025

VMware has released a security update to address a vulnerability affecting VMware Avi Load Balancer.

The addressed vulnerability could allow the remote attacker to perform blind SQL injection attacks and gain access to the affected system.

VMware Avi Load Balancer unauthenticated Blind SQL Injection Vulnerability (CVE-2025-22217):

  • CVSS: 8.6
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities

CVE-2025-22217

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

VMware Security Update

References