<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 10:32:46 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-41233</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-41233</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; VMware Avi Load Balancer&lt;/p&gt;
&lt;p&gt;Description:&lt;/p&gt;
&lt;p&gt;VMware AVI Load Balancer contains an authenticated blind SQL Injection vulnerability. VMware has evaluated the severity of the issue to be in the  Moderate severity range https://www.broadcom.com/support/vmware-services/security-response  with a maximum CVSSv3 base score of  6.8 https://www.first.org/cvss/calculator/3-0#CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N .&lt;/p&gt;
&lt;p&gt;Known Attack Vectors:&lt;/p&gt;
&lt;p&gt;An authenticated malicious user with network access may be able to use specially crafted SQL queries to gain database access.&lt;/p&gt;
&lt;p&gt;Resolution:&lt;/p&gt;
&lt;p&gt;To remediate CVE-2025-41233 apply the patches to the Avi Controller listed in the &amp;#39;Fixed Version&amp;#39; column of the &amp;#39;Response Matrix&amp;#39; found below.&lt;/p&gt;
&lt;p&gt;Workarounds:&lt;/p&gt;
&lt;p&gt;None.&lt;/p&gt;
&lt;p&gt;Additional Documentation:&lt;/p&gt;
&lt;p&gt;None.&lt;/p&gt;
&lt;p&gt;Acknowledgements:&lt;/p&gt;
&lt;p&gt;VMware would like to thank  Alexandru Copaceanu https://www.linkedin.com/in/alexandru-copaceanu-b39aaa1a8/  for reporting this issue to us.&lt;/p&gt;
&lt;p&gt;Notes:&lt;/p&gt;
&lt;p&gt;None.&lt;/p&gt;
&lt;p&gt;Response Matrix:&lt;/p&gt;
&lt;p&gt;ProductVersionRunning OnCVECVSSv4SeverityFixed VersionWorkaroundsAdditional DocumentsVMware Avi Load Balancer30.1.1AnyCVE-2025-41233 6.8 https://www.first.org/cvss/calculator/3-0#CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N Moderate 30.1.2-2p3 https://techdocs.broadcom.com/us/en/vmware-security-load-balancing/avi-load-balancer/avi-load-balancer/30-1/vmware-avi-load-balancer-release-notes/release-notes-30-1-2.html NoneNoneVMware Avi Load Balancer30.1.2AnyCVE-2025-41233 6.8 https://www.first.org/cvss/calculator/3-0#CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; VMware Avi Load Balancer&lt;/p&gt;
&lt;p&gt;Description:&lt;/p&gt;
&lt;p&gt;VMware AVI Load Balancer contains an authenticated blind SQL Injection vulnerability. VMware has evaluated the severity of the issue to be in the  Moderate severity range https://www.broadcom.com/support/vmware-services/security-response  with a maximum CVSSv3 base score of  6.8 https://www.first.org/cvss/calculator/3-0#CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N .&lt;/p&gt;
&lt;p&gt;Known Attack Vectors:&lt;/p&gt;
&lt;p&gt;An authenticated malicious user with network access may be able to use specially crafted SQL queries to gain database access.&lt;/p&gt;
&lt;p&gt;Resolution:&lt;/p&gt;
&lt;p&gt;To remediate CVE-2025-41233 apply the patches to the Avi Controller listed in the &amp;#39;Fixed Version&amp;#39; column of the &amp;#39;Response Matrix&amp;#39; found below.&lt;/p&gt;
&lt;p&gt;Workarounds:&lt;/p&gt;
&lt;p&gt;None.&lt;/p&gt;
&lt;p&gt;Additional Documentation:&lt;/p&gt;
&lt;p&gt;None.&lt;/p&gt;
&lt;p&gt;Acknowledgements:&lt;/p&gt;
&lt;p&gt;VMware would like to thank  Alexandru Copaceanu https://www.linkedin.com/in/alexandru-copaceanu-b39aaa1a8/  for reporting this issue to us.&lt;/p&gt;
&lt;p&gt;Notes:&lt;/p&gt;
&lt;p&gt;None.&lt;/p&gt;
&lt;p&gt;Response Matrix:&lt;/p&gt;
&lt;p&gt;ProductVersionRunning OnCVECVSSv4SeverityFixed VersionWorkaroundsAdditional DocumentsVMware Avi Load Balancer30.1.1AnyCVE-2025-41233 6.8 https://www.first.org/cvss/calculator/3-0#CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N Moderate 30.1.2-2p3 https://techdocs.broadcom.com/us/en/vmware-security-load-balancing/avi-load-balancer/avi-load-balancer/30-1/vmware-avi-load-balancer-release-notes/release-notes-30-1-2.html NoneNoneVMware Avi Load Balancer30.1.2AnyCVE-2025-41233 6.8 https://www.first.org/cvss/calculator/3-0#CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-41233</guid>
    </item>
  </channel>
</rss>
