VMSA-2025-0011 – VMware Avi Load Balancer – SQL Injection Vulnerability
VMware by Broadcom addresses VMware Avi Load Balancer an authenticated blind SQL Injection vulnerability CVE-2025-41233. Avi Load Balancer contains an authenticated blind SQL Injection vulnerability, which was privately reported to VMware. Patches are available to remediate this vulnerability in affected VMware products. An authenticated malicious user with network access may be able to use specially crafted SQL queries to gain database access.
Impacted Products
- VMware Avi Load Balancer
CVE-2025-41233 | VMware Avi Load Balancer Blind SQL Injection vulnerability
Description:
VMware AVI Load Balancer contains an authenticated blind SQL Injection vulnerability. VMware has evaluated the severity of the issue to be in the Moderate severity range with a maximum CVSSv3 base score of 6.8.
Resolution:
To remediate CVE-2025-41233 apply the patches to the Avi Controller listed in the ‘Fixed Version’ column of the ‘Response Matrix’ found below.
Response Matrix:
Product | Version | CVE | Severity | Fixed Version | Workarounds |
VMware Avi Load Balancer | 30.1.1 | CVE-2025-41233 | Moderate | 30.1.2-2p3 | None |
VMware Avi Load Balancer | 30.1.2 | CVE-2025-41233 | Moderate | 30.1.2-2p3 | None |
VMware Avi Load Balancer | 30.2.1 | CVE-2025-41233 | Moderate | 30.2.1-2p6 | None |
VMware Avi Load Balancer | 30.2.2 | CVE-2025-41233 | Moderate | 30.2.2-2p5 | None |
VMware Avi Load Balancer | 30.2.3 | CVE-2025-41233 | Moderate | 30.2.3 | None |
VMware Avi Load Balancer | 31.1.1 | CVE-2025-41233 | Moderate | 31.1.1-2p2 | None |
Sources:
Broadcom Blog Post
Fixed Version(s) and Release Notes:
30.1.1/30.1.2
30.2.1
30.2.2
30.2.3
31.1.1