Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version 20.0.2786 (VA and SaaS deployments) contain a private SSL key and matching public certificate stored in cleartext. The key belongs to the hostname `pl‑local.com` and is used by the appliance to terminate TLS connections on ports 80/443. Because the key is hardcoded, any attacker who can gain container-level access can simply read the files and obtain the private key. With the private key, the attacker can decrypt TLS traffic, perform man-in-the-middle attacks, or forge TLS certificates. This enables impersonation of the appliance’s web UI, interception of credentials, and unrestricted access to any services that trust the certificate. The same key is identical across all deployed appliances meaning a single theft compromises the confidentiality of every Vasion Print installation. This vulnerability has been identified by the vendor as: V-2024-025 — Hardcoded SSL Certificate & Private Keys.
The SSL private key assigned to the hostname `pl-local.com` is used by the device to terminate TLS connections on ports 80 and 443. The key is stored in files within the container in unencrypted cleartext. An attacker who gains container-level access can read the key files without any additional privileges. Since the identical key is embedded in every product deployment, obtaining it from one instance enables attacks on all remaining installations.
An attacker possessing the stolen key can decrypt intercepted TLS traffic, conduct man-in-the-middle attacks, impersonate the device's web interface, and intercept user credentials. It is also possible to forge TLS certificates and gain unrestricted access to services that trust this certificate.
Update Virtual Appliance Host to version 22.0.1049 or later and Virtual Appliance Application to version 20.0.2786 or later. Additional details are available in the vendor's security bulletins at the reference addresses. After applying patches, verify that new deployments no longer contain the shared key and consider inspecting network traffic for signs of potential previous MITM attacks.
Vasion Print (formerly PrinterLogic) Virtual Appliance Host in versions prior to 22.0.1049 and Virtual Appliance Application in versions prior to 20.0.2786 — affects both VA and SaaS deployments.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XVasion Virtual Appliance Application
APPVasion< 20.0.2786Vasion Virtual Appliance Host
APPVasion< 22.0.1049
Related vulnerabilities
Vasion Print Virtual Appliance — hasła w plikach plaintext dostępnych dla wszystkich
Vasion Print: hardcoded SSH key umożliwiający root access do appliance
Vasion Print Virtual Appliance — nieautoryzowane RCE przez firmware-upload
Hardcoded klucz prywatny GPG w Vasion Print Virtual Appliance
Vasion Print: hardcoded klucz prywatny CA i hasło w plikach konfiguracyjnych