Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application prior to 25.1.1413 (Windows client deployments) contain a hardcoded private key for the PrinterLogic Certificate Authority (CA) and a hardcoded password in product configuration files. The Windows client ships the CA certificate and its associated private key (and other sensitive settings such as a configured password) directly in shipped configuration files (for example clientsettings.dat and defaults.ini). An attacker who obtains these files can impersonate the CA, sign arbitrary certificates trusted by the Windows client, intercept or decrypt TLS-protected communications, and otherwise perform man-in-the-middle or impersonation attacks against the product's network communications. This vulnerability has been identified by the vendor as: V-2022-001 — Configuration File Contains CA & Private Key.
Windows client configuration files (including clientsettings.dat and defaults.ini) contain the PrinterLogic CA certificate along with its associated private key and a hardcoded password. An attacker who gains access to these files can use the CA private key to sign arbitrary certificates accepted by the Windows client. This enables interception and decryption of traffic protected by TLS and allows conducting impersonation and man-in-the-middle attacks against the product's network communications.
An attacker can impersonate a trusted certificate authority, sign arbitrary certificates, intercept and decrypt encrypted TLS communications, and conduct man-in-the-middle and impersonation attacks against Vasion Print infrastructure.
Virtual Appliance Host must be updated to version 25.1.102 or later and Application (Windows client) to version 25.1.1413 or later. Patches and details are available in the vendor's security bulletins at the addresses indicated in the references. After updating, it is recommended to revoke previously issued certificates signed by the compromised CA and replace all passwords stored in configuration files.
Vasion Print (formerly PrinterLogic) Virtual Appliance Host in versions prior to 25.1.102 and Application (Windows client) in versions prior to 25.1.1413
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMicrosoft Windows
OSMicrosoftall versionsVasion Virtual Appliance Application
APPVasion< 25.1.1413Vasion Virtual Appliance Host
APPVasion< 25.1.102
Related vulnerabilities
Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP
Path Traversal w Kingsoft WPS Office — ładowanie dowolnej biblioteki Windows
PHP CGI argument injection – RCE na Windows przez mechanizm Best-Fit