7.1
CVE-2025-34193 - Vasion Print (formerly PrinterLogic) Insecure Windows Components Lack Modern Memory Protections and…
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application versions prior to 25.1.1413 include Windows client components (PrinterInstallerClientInterface.exe, PrinterInstallerClient.exe, PrinterInstallerClientLauncher.exe) that lack modern compile-time an…
8.5
CVE-2025-34201 - Vasion Print (formerly PrinterLogic) Lack of Network Segmentation Between Docker Instances
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) run many Docker containers on shared internal networks without firewalling or segmentation between instances. A compromise of any single container allows direct access to internal services (HTTP, R…
8.4
CVE-2025-34188 - Vasion Print (formerly PrinterLogic) Local Log Disclosure of Cleartext Sessions
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application prior to 20.0.1330 (macOS/Linux client deployments) contain a vulnerability in the local logging mechanism. Authentication session tokens, including PHPSESSID, XSRF-TOKEN, and laravel_session, are …
8.5
CVE-2025-34194 - Vasion Print (formerly PrinterLogic) Local Privilege Escalation via Insecure Temporary File Handling
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application versions prior to 25.1.1413 (Windows client deployments) contain an insecure temporary-file handling vulnerability in the PrinterInstallerClient components. The software creates files as NT AUTHOR…
8.6
CVE-2025-34200 - Vasion Print (formerly PrinterLogic) Network Account Password Stored in Cleartext
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) provision the appliance with the network account credentials in clear-text inside /etc/issue, and the file is world-readable by default. An attacker with local shell access can read /etc/issue to …
8.7
CVE-2025-34204 - Vasion Print (formerly PrinterLogic) Processes Running as Root Inside Docker Instances
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) contains multiple Docker containers that run primary application processes (for example PHP workers, Node.js servers and custom binaries) as the root user. This increases the blast radius of a cont…
9.3
CVE-2025-34198 - Vasion Print (formerly PrinterLogic) Shared / Hardcoded SSH Host Private Keys in Appliance Image
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.951 and Application prior to 20.0.2368 (VA and SaaS deployments) contain shared, hardcoded SSH host private keys in the appliance image. The same private host keys (RSA, ECDSA, and ED25519) are present across install…
8.6
CVE-2025-34197 - Vasion Print (formerly PrinterLogic) Undocumented Local Account with Hardcoded Password and Passwor…
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.951, Application prior to 20.0.2368 (VA and SaaS deployments) contain an undocumented local user account named ubuntu with a preset password and a sudoers entry granting that account passwordless root privileges (ubu…
9.3
CVE-2025-34192 - Vasion Print (formerly PrinterLogic) Usage of Outdated and Unsupported OpenSSL Version
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.893 and Application versions prior to 20.0.2140 (macOS/Linux client deployments) are built against OpenSSL 1.0.2h-fips (released May 2016), which has been end-of-life since 2019 and is no longer supported by the Open…
8.6
CVE-2025-34195 - Vasion Print (formerly PrinterLogic) Unquoted Path During Driver Installation Leads to Execution of…
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application prior to 20.0.1330 (Windows client deployments) contain a remote code execution vulnerability during driver installation caused by unquoted program paths. The PrinterInstallerClient driver-installa…