CRITICAL🇵🇱 Wersja polska

CVE-2025-34210

CVSS 9.4v4.0pub. 2025-10-02upd. 2025-10-09

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) store a large number of sensitive credentials (database passwords, MySQL root password, SaaS keys, Portainer admin password, etc.) in cleartext files that are world-readable. Any local user - or any process that can read the host filesystem - can retrieve all of these secrets in plain text, leading to credential theft and full compromise of the appliance. The vendor does not consider this to be a security vulnerability as this product "follows a shared responsibility model, where administrators are expected to configure persistent storage encryption."

🤖 AI Analysis
How it works

The vulnerability results from CWE-256 classified storage of passwords in unencrypted form (plaintext). Files containing credentials are marked with world-readable permissions, meaning any user or process running on the host can read them without any additional privileges. An attacker who gains minimal local access (e.g., through another vulnerability) can read a complete set of critical passwords with a single command — database credentials, MySQL root password, SaaS keys, and Portainer administrator account password. The manufacturer does not recognize this as a security vulnerability, citing the shared responsibility model and the expectation that administrators will configure storage encryption.

Impact

An attacker gains access to a complete set of critical credentials of the Virtual Appliance environment, which in practice means full compromise of the device — including access to the database, container infrastructure (Portainer), and integration keys with SaaS services.

Mitigation & patch

The manufacturer has not released a patch, as they do not recognize the issue as a security vulnerability. Recommended compensatory actions: enable encryption of persistent storage in accordance with the manufacturer's documentation (shared responsibility model), restrict local access to the host exclusively to trusted administrative accounts, apply the principle of least privilege for processes running on the host, monitor unauthorized access to configuration files. You should monitor the manufacturer's security bulletins at the addresses indicated in the references.

Who is affected

Vasion Print (formerly PrinterLogic) Virtual Appliance Application and Virtual Appliance Host in VA/SaaS deployments; specific versions indicated in the manufacturer's references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Vasion Virtual Appliance Application

    APP
    Vasion
    all versions
  • Vasion Virtual Appliance Host

    APP
    Vasion
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-34217CRITICAL10.0PL ✓same product

Vasion Print: hardcoded SSH key umożliwiający root access do appliance

CVE-2025-34215CRITICAL9.4PL ✓same product

Vasion Print Virtual Appliance — nieautoryzowane RCE przez firmware-upload

CVE-2025-34196CRITICAL9.3PL ✓same product

Vasion Print: hardcoded klucz prywatny CA i hasło w plikach konfiguracyjnych

CVE-2025-34209CRITICAL9.4PL ✓same product

Hardcoded klucz prywatny GPG w Vasion Print Virtual Appliance

CVE-2025-34211CRITICAL9.3PL ✓same product

Vasion Print: hardcoded klucz prywatny SSL we wszystkich instancjach