Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.893 and Application versions prior to 20.0.2140 (macOS/Linux client deployments) are built against OpenSSL 1.0.2h-fips (released May 2016), which has been end-of-life since 2019 and is no longer supported by the OpenSSL project. Continued use of this outdated cryptographic library exposes deployments to known vulnerabilities that are no longer patched, weakening the overall security posture. Affected daemons may emit deprecation warnings and rely on cryptographic components with unresolved security flaws, potentially enabling attackers to exploit weaknesses in TLS/SSL processing or cryptographic operations. This vulnerability has been identified by the vendor as: V-2023-021 — Out-of-Date OpenSSL Library.
The vulnerability results from the use of an external component (OpenSSL 1.0.2h-fips) that has received no security updates since 2019 (CWE-1104 — use of outdated external component). Vasion Print software compiles embedded daemons with this library, so known vulnerabilities in TLS/SSL and cryptographic operations remain permanently unpatched. Affected daemons may emit deprecation warnings and use cryptographic components with unresolved weaknesses. A remote attacker, without authentication, may attempt to exploit these weaknesses when processing TLS/SSL traffic.
An attacker may potentially exploit known vulnerabilities in the outdated OpenSSL library to compromise the confidentiality, integrity, or availability of processed data — including data transmitted over an encrypted TLS/SSL channel.
Virtual Appliance Host must be updated to version 22.0.893 or later, and Application to version 20.0.2140 or later. Detailed information on available patches is available in the vendor's security bulletins at the addresses indicated in the references (vendor's internal vulnerability identifier: V-2023-021).
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions below 22.0.893 and Virtual Appliance Application versions below 20.0.2140 (macOS/Linux customer deployments).
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XApple macOS
OSAppleall versionsLinux Kernel
OSLinuxall versionsVasion Virtual Appliance Application
APPVasion< 20.0.2140Vasion Virtual Appliance Host
APPVasion< 22.0.893
Related vulnerabilities
Pominięcie uwierzytelniania w Screen Sharing na macOS
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP
Apple: Obejście Pointer Authentication w iOS, macOS i innych platformach