CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-34215

CVSS 9.4v4.0pub. 2025-09-29upd. 2025-10-18

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1026 and Application prior to version 20.0.2702 (only VA deployments) expose an unauthenticated firmware-upload flow: a public page returns a signed token usable at va-api/v1/update, and every Docker image contains the appliance’s private GPG key and hard-coded passphrase. An attacker who extracts the key and obtains a token can decrypt, modify, re-sign, upload, and trigger malicious firmware, gaining remote code execution. This vulnerability has been identified by the vendor as: V-2024-020 — Remote Code Execution.

🤖 AI Analysis
How it works

The public application page returns a signed token authorizing the invocation of the va-api/v1/update endpoint. At the same time, each Docker image contains the appliance's private GPG key along with a hardcoded password (CWE-321), which enables decryption of the original firmware. An attacker who obtains the key and token can modify the firmware, re-sign it, upload it to the endpoint, and trigger its installation — thereby gaining full RCE. The absence of any authentication mechanism when retrieving the token (CWE-306) makes the attack available to anyone with network access to the appliance.

Impact

An attacker gains remote code execution (RCE) at the appliance level, which can lead to full takeover of the virtual system, its container environment, and potentially the entire print infrastructure.

Mitigation & patch

Update Virtual Appliance Host to version 22.0.1026 or newer and Virtual Appliance Application to version 20.0.2702 or newer. Detailed information is available in the vendor's security bulletins at help.printerlogic.com. Until the patch is deployed, it is recommended to restrict network access to the va-api/v1/update endpoint at the firewall level.

Who is affected

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions earlier than 22.0.1026 and Virtual Appliance Application versions earlier than 20.0.2702 — VA (Virtual Appliance) deployments only.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Vasion Virtual Appliance Application

    APP
    Vasion
    < 20.0.2702
  • Vasion Virtual Appliance Host

    APP
    Vasion
    < 22.0.1026
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCEContainer
CWE
References

Related vulnerabilities

CVE-2025-34210CRITICAL9.4PL ✓same product

Vasion Print Virtual Appliance — hasła w plikach plaintext dostępnych dla wszystkich

CVE-2025-34217CRITICAL10.0PL ✓same product

Vasion Print: hardcoded SSH key umożliwiający root access do appliance

CVE-2025-34211CRITICAL9.3PL ✓same product

Vasion Print: hardcoded klucz prywatny SSL we wszystkich instancjach

CVE-2025-34209CRITICAL9.4PL ✓same product

Hardcoded klucz prywatny GPG w Vasion Print Virtual Appliance

CVE-2025-34196CRITICAL9.3PL ✓same product

Vasion Print: hardcoded klucz prywatny CA i hasło w plikach konfiguracyjnych