CRITICAL🇵🇱 Wersja polska

CVE-2025-34209

CVSS 9.4v4.0pub. 2025-09-29upd. 2025-10-03

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to 22.0.862 and Application prior to 20.0.2014 (VA and SaaS deployments) contain Docker images with the private GPG key and passphrase for the account *no‑reply+virtual‑appliance@printerlogic.com*. The key is stored in cleartext and the passphrase is hardcoded in files. An attacker with administrative access to the appliance can extract the private key, import it into their own system, and subsequently decrypt GPG-encrypted files and sign arbitrary firmware update packages. A maliciously signed update can be uploaded by an admin‑level attacker and will be executed by the appliance, giving the attacker full control of the virtual appliance. This vulnerability has been identified by the vendor as: V-2023-010 — Hardcoded Private Key.

🤖 AI Analysis
How it works

The GPG private key associated with the no-reply+virtual-appliance@printerlogic.com account is stored in plaintext within Docker images supplied with the application, and the key passphrase is hardcoded in system files. An attacker with administrative access to the device can extract the private key and import it into their own system. Subsequently, they can decrypt GPG-encrypted files and sign arbitrary firmware update packages so that the system recognizes them as authentic. A malicious signed update uploaded by the attacker will be executed by the appliance, granting the attacker full control over the device.

Impact

An attacker with administrative privileges can gain full control over the Virtual Appliance, including the ability to decrypt sensitive data and distribute malicious firmware updates. This results in complete device takeover and potential compromise of the printing environment integrity.

Mitigation & patch

Update Virtual Appliance Host to version 22.0.862 or later and Virtual Appliance Application to version 20.0.2014 or later. Patches are available according to vendor security bulletins at the addresses indicated in the references. Until the update is applied, it is recommended to restrict administrative access to the appliance to trusted and strictly controlled accounts only.

Who is affected

Vasion Print (formerly PrinterLogic) Virtual Appliance Host in versions prior to 22.0.862 and Virtual Appliance Application in versions prior to 20.0.2014 — affecting VA and SaaS deployments.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Vasion Virtual Appliance Application

    APP
    Vasion
    < 20.0.2014
  • Vasion Virtual Appliance Host

    APP
    Vasion
    < 22.0.862
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Container
CWE
References

Related vulnerabilities

CVE-2025-34210CRITICAL9.4PL ✓same product

Vasion Print Virtual Appliance — hasła w plikach plaintext dostępnych dla wszystkich

CVE-2025-34217CRITICAL10.0PL ✓same product

Vasion Print: hardcoded SSH key umożliwiający root access do appliance

CVE-2025-34215CRITICAL9.4PL ✓same product

Vasion Print Virtual Appliance — nieautoryzowane RCE przez firmware-upload

CVE-2025-34196CRITICAL9.3PL ✓same product

Vasion Print: hardcoded klucz prywatny CA i hasło w plikach konfiguracyjnych

CVE-2025-34211CRITICAL9.3PL ✓same product

Vasion Print: hardcoded klucz prywatny SSL we wszystkich instancjach