CRITICAL🇵🇱 Wersja polska

CVE-2025-34211

CVSS 9.3v4.0pub. 2025-09-29upd. 2025-10-03

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version 20.0.2786 (VA and SaaS deployments) contain a private SSL key and matching public certificate stored in cleartext. The key belongs to the hostname `pl‑local.com` and is used by the appliance to terminate TLS connections on ports 80/443. Because the key is hardcoded, any attacker who can gain container-level access can simply read the files and obtain the private key. With the private key, the attacker can decrypt TLS traffic, perform man-in-the-middle attacks, or forge TLS certificates. This enables impersonation of the appliance’s web UI, interception of credentials, and unrestricted access to any services that trust the certificate. The same key is identical across all deployed appliances meaning a single theft compromises the confidentiality of every Vasion Print installation. This vulnerability has been identified by the vendor as: V-2024-025 — Hardcoded SSL Certificate & Private Keys.

🤖 AI Analysis
How it works

The SSL private key assigned to the hostname `pl-local.com` is used by the device to terminate TLS connections on ports 80 and 443. The key is stored in files within the container in unencrypted cleartext. An attacker who gains container-level access can read the key files without any additional privileges. Since the identical key is embedded in every product deployment, obtaining it from one instance enables attacks on all remaining installations.

Impact

An attacker possessing the stolen key can decrypt intercepted TLS traffic, conduct man-in-the-middle attacks, impersonate the device's web interface, and intercept user credentials. It is also possible to forge TLS certificates and gain unrestricted access to services that trust this certificate.

Mitigation & patch

Update Virtual Appliance Host to version 22.0.1049 or later and Virtual Appliance Application to version 20.0.2786 or later. Additional details are available in the vendor's security bulletins at the reference addresses. After applying patches, verify that new deployments no longer contain the shared key and consider inspecting network traffic for signs of potential previous MITM attacks.

Who is affected

Vasion Print (formerly PrinterLogic) Virtual Appliance Host in versions prior to 22.0.1049 and Virtual Appliance Application in versions prior to 20.0.2786 — affects both VA and SaaS deployments.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Vasion Virtual Appliance Application

    APP
    Vasion
    < 20.0.2786
  • Vasion Virtual Appliance Host

    APP
    Vasion
    < 22.0.1049
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Container
CWE
References

Related vulnerabilities

CVE-2025-34210CRITICAL9.4PL ✓same product

Vasion Print Virtual Appliance — hasła w plikach plaintext dostępnych dla wszystkich

CVE-2025-34217CRITICAL10.0PL ✓same product

Vasion Print: hardcoded SSH key umożliwiający root access do appliance

CVE-2025-34215CRITICAL9.4PL ✓same product

Vasion Print Virtual Appliance — nieautoryzowane RCE przez firmware-upload

CVE-2025-34209CRITICAL9.4PL ✓same product

Hardcoded klucz prywatny GPG w Vasion Print Virtual Appliance

CVE-2025-34196CRITICAL9.3PL ✓same product

Vasion Print: hardcoded klucz prywatny CA i hasło w plikach konfiguracyjnych