Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) store a large number of sensitive credentials (database passwords, MySQL root password, SaaS keys, Portainer admin password, etc.) in cleartext files that are world-readable. Any local user - or any process that can read the host filesystem - can retrieve all of these secrets in plain text, leading to credential theft and full compromise of the appliance. The vendor does not consider this to be a security vulnerability as this product "follows a shared responsibility model, where administrators are expected to configure persistent storage encryption."
The vulnerability results from CWE-256 classified storage of passwords in unencrypted form (plaintext). Files containing credentials are marked with world-readable permissions, meaning any user or process running on the host can read them without any additional privileges. An attacker who gains minimal local access (e.g., through another vulnerability) can read a complete set of critical passwords with a single command — database credentials, MySQL root password, SaaS keys, and Portainer administrator account password. The manufacturer does not recognize this as a security vulnerability, citing the shared responsibility model and the expectation that administrators will configure storage encryption.
An attacker gains access to a complete set of critical credentials of the Virtual Appliance environment, which in practice means full compromise of the device — including access to the database, container infrastructure (Portainer), and integration keys with SaaS services.
The manufacturer has not released a patch, as they do not recognize the issue as a security vulnerability. Recommended compensatory actions: enable encryption of persistent storage in accordance with the manufacturer's documentation (shared responsibility model), restrict local access to the host exclusively to trusted administrative accounts, apply the principle of least privilege for processes running on the host, monitor unauthorized access to configuration files. You should monitor the manufacturer's security bulletins at the addresses indicated in the references.
Vasion Print (formerly PrinterLogic) Virtual Appliance Application and Virtual Appliance Host in VA/SaaS deployments; specific versions indicated in the manufacturer's references
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XVasion Virtual Appliance Application
APPVasionall versionsVasion Virtual Appliance Host
APPVasionall versions
Related vulnerabilities
Vasion Print: hardcoded SSH key umożliwiający root access do appliance
Vasion Print Virtual Appliance — nieautoryzowane RCE przez firmware-upload
Vasion Print: hardcoded klucz prywatny CA i hasło w plikach konfiguracyjnych
Hardcoded klucz prywatny GPG w Vasion Print Virtual Appliance
Vasion Print: hardcoded klucz prywatny SSL we wszystkich instancjach