CRITICAL🇵🇱 Wersja polska

CVE-2025-34196

CVSS 9.3v4.0pub. 2025-09-29upd. 2025-10-16

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application prior to 25.1.1413 (Windows client deployments) contain a hardcoded private key for the PrinterLogic Certificate Authority (CA) and a hardcoded password in product configuration files. The Windows client ships the CA certificate and its associated private key (and other sensitive settings such as a configured password) directly in shipped configuration files (for example clientsettings.dat and defaults.ini). An attacker who obtains these files can impersonate the CA, sign arbitrary certificates trusted by the Windows client, intercept or decrypt TLS-protected communications, and otherwise perform man-in-the-middle or impersonation attacks against the product's network communications. This vulnerability has been identified by the vendor as: V-2022-001 — Configuration File Contains CA & Private Key.

🤖 AI Analysis
How it works

Windows client configuration files (including clientsettings.dat and defaults.ini) contain the PrinterLogic CA certificate along with its associated private key and a hardcoded password. An attacker who gains access to these files can use the CA private key to sign arbitrary certificates accepted by the Windows client. This enables interception and decryption of traffic protected by TLS and allows conducting impersonation and man-in-the-middle attacks against the product's network communications.

Impact

An attacker can impersonate a trusted certificate authority, sign arbitrary certificates, intercept and decrypt encrypted TLS communications, and conduct man-in-the-middle and impersonation attacks against Vasion Print infrastructure.

Mitigation & patch

Virtual Appliance Host must be updated to version 25.1.102 or later and Application (Windows client) to version 25.1.1413 or later. Patches and details are available in the vendor's security bulletins at the addresses indicated in the references. After updating, it is recommended to revoke previously issued certificates signed by the compromised CA and replace all passwords stored in configuration files.

Who is affected

Vasion Print (formerly PrinterLogic) Virtual Appliance Host in versions prior to 25.1.102 and Application (Windows client) in versions prior to 25.1.1413

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Microsoft Windows

    OS
    Microsoft
    all versions
  • Vasion Virtual Appliance Application

    APP
    Vasion
    < 25.1.1413
  • Vasion Virtual Appliance Host

    APP
    Vasion
    < 25.1.102
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-8398CRITICAL9.3⚠ KEVPL ✓same product

Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product

Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP

CVE-2024-7262CRITICAL9.3⚠ KEVPL ✓same product

Path Traversal w Kingsoft WPS Office — ładowanie dowolnej biblioteki Windows

CVE-2024-4577CRITICAL9.8⚠ KEVPL ✓same product

PHP CGI argument injection – RCE na Windows przez mechanizm Best-Fit