CRITICAL🇵🇱 Wersja polska

CVE-2025-34192

CVSS 9.3v4.0pub. 2025-09-19upd. 2025-10-02

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.893 and Application versions prior to 20.0.2140 (macOS/Linux client deployments) are built against OpenSSL 1.0.2h-fips (released May 2016), which has been end-of-life since 2019 and is no longer supported by the OpenSSL project. Continued use of this outdated cryptographic library exposes deployments to known vulnerabilities that are no longer patched, weakening the overall security posture. Affected daemons may emit deprecation warnings and rely on cryptographic components with unresolved security flaws, potentially enabling attackers to exploit weaknesses in TLS/SSL processing or cryptographic operations. This vulnerability has been identified by the vendor as: V-2023-021 — Out-of-Date OpenSSL Library.

🤖 AI Analysis
How it works

The vulnerability results from the use of an external component (OpenSSL 1.0.2h-fips) that has received no security updates since 2019 (CWE-1104 — use of outdated external component). Vasion Print software compiles embedded daemons with this library, so known vulnerabilities in TLS/SSL and cryptographic operations remain permanently unpatched. Affected daemons may emit deprecation warnings and use cryptographic components with unresolved weaknesses. A remote attacker, without authentication, may attempt to exploit these weaknesses when processing TLS/SSL traffic.

Impact

An attacker may potentially exploit known vulnerabilities in the outdated OpenSSL library to compromise the confidentiality, integrity, or availability of processed data — including data transmitted over an encrypted TLS/SSL channel.

Mitigation & patch

Virtual Appliance Host must be updated to version 22.0.893 or later, and Application to version 20.0.2140 or later. Detailed information on available patches is available in the vendor's security bulletins at the addresses indicated in the references (vendor's internal vulnerability identifier: V-2023-021).

Who is affected

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions below 22.0.893 and Virtual Appliance Application versions below 20.0.2140 (macOS/Linux customer deployments).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Apple macOS

    OS
    Apple
    all versions
  • Linux Kernel

    OS
    Linux
    all versions
  • Vasion Virtual Appliance Application

    APP
    Vasion
    < 20.0.2140
  • Vasion Virtual Appliance Host

    APP
    Vasion
    < 22.0.893
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-65400CRITICAL9.8⚠ KEVPL ✓same product

Pominięcie uwierzytelniania w Screen Sharing na macOS

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2025-43300CRITICAL10.0⚠ KEVPL ✓same product

Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu

CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product

Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP

CVE-2025-31201CRITICAL9.8⚠ KEVPL ✓same product

Apple: Obejście Pointer Authentication w iOS, macOS i innych platformach