Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to 22.0.862 and Application prior to 20.0.2014 (VA and SaaS deployments) contain Docker images with the private GPG key and passphrase for the account *no‑reply+virtual‑appliance@printerlogic.com*. The key is stored in cleartext and the passphrase is hardcoded in files. An attacker with administrative access to the appliance can extract the private key, import it into their own system, and subsequently decrypt GPG-encrypted files and sign arbitrary firmware update packages. A maliciously signed update can be uploaded by an admin‑level attacker and will be executed by the appliance, giving the attacker full control of the virtual appliance. This vulnerability has been identified by the vendor as: V-2023-010 — Hardcoded Private Key.
The GPG private key associated with the no-reply+virtual-appliance@printerlogic.com account is stored in plaintext within Docker images supplied with the application, and the key passphrase is hardcoded in system files. An attacker with administrative access to the device can extract the private key and import it into their own system. Subsequently, they can decrypt GPG-encrypted files and sign arbitrary firmware update packages so that the system recognizes them as authentic. A malicious signed update uploaded by the attacker will be executed by the appliance, granting the attacker full control over the device.
An attacker with administrative privileges can gain full control over the Virtual Appliance, including the ability to decrypt sensitive data and distribute malicious firmware updates. This results in complete device takeover and potential compromise of the printing environment integrity.
Update Virtual Appliance Host to version 22.0.862 or later and Virtual Appliance Application to version 20.0.2014 or later. Patches are available according to vendor security bulletins at the addresses indicated in the references. Until the update is applied, it is recommended to restrict administrative access to the appliance to trusted and strictly controlled accounts only.
Vasion Print (formerly PrinterLogic) Virtual Appliance Host in versions prior to 22.0.862 and Virtual Appliance Application in versions prior to 20.0.2014 — affecting VA and SaaS deployments.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XVasion Virtual Appliance Application
APPVasion< 20.0.2014Vasion Virtual Appliance Host
APPVasion< 22.0.862
Related vulnerabilities
Vasion Print Virtual Appliance — hasła w plikach plaintext dostępnych dla wszystkich
Vasion Print: hardcoded SSH key umożliwiający root access do appliance
Vasion Print Virtual Appliance — nieautoryzowane RCE przez firmware-upload
Vasion Print: hardcoded klucz prywatny CA i hasło w plikach konfiguracyjnych
Vasion Print: hardcoded klucz prywatny SSL we wszystkich instancjach