Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1026 and Application prior to version 20.0.2702 (only VA deployments) expose an unauthenticated firmware-upload flow: a public page returns a signed token usable at va-api/v1/update, and every Docker image contains the appliance’s private GPG key and hard-coded passphrase. An attacker who extracts the key and obtains a token can decrypt, modify, re-sign, upload, and trigger malicious firmware, gaining remote code execution. This vulnerability has been identified by the vendor as: V-2024-020 — Remote Code Execution.
The public application page returns a signed token authorizing the invocation of the va-api/v1/update endpoint. At the same time, each Docker image contains the appliance's private GPG key along with a hardcoded password (CWE-321), which enables decryption of the original firmware. An attacker who obtains the key and token can modify the firmware, re-sign it, upload it to the endpoint, and trigger its installation — thereby gaining full RCE. The absence of any authentication mechanism when retrieving the token (CWE-306) makes the attack available to anyone with network access to the appliance.
An attacker gains remote code execution (RCE) at the appliance level, which can lead to full takeover of the virtual system, its container environment, and potentially the entire print infrastructure.
Update Virtual Appliance Host to version 22.0.1026 or newer and Virtual Appliance Application to version 20.0.2702 or newer. Detailed information is available in the vendor's security bulletins at help.printerlogic.com. Until the patch is deployed, it is recommended to restrict network access to the va-api/v1/update endpoint at the firewall level.
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions earlier than 22.0.1026 and Virtual Appliance Application versions earlier than 20.0.2702 — VA (Virtual Appliance) deployments only.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XVasion Virtual Appliance Application
APPVasion< 20.0.2702Vasion Virtual Appliance Host
APPVasion< 22.0.1026
Related vulnerabilities
Vasion Print Virtual Appliance — hasła w plikach plaintext dostępnych dla wszystkich
Vasion Print: hardcoded SSH key umożliwiający root access do appliance
Vasion Print: hardcoded klucz prywatny SSL we wszystkich instancjach
Hardcoded klucz prywatny GPG w Vasion Print Virtual Appliance
Vasion Print: hardcoded klucz prywatny CA i hasło w plikach konfiguracyjnych