📦 Virtual Appliance Application

by Vasion

🔍 What is Virtual Appliance Application?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-34217

CRITICAL CVSS 9.8 Sep 30, 2025

This vulnerability allows attackers with the matching private SSH key to gain root access to Vasion Print (formerly PrinterLogic) Virtual Appliance systems. The undocumented 'printerlogic' user has a ...

CVE-2025-34223

CRITICAL CVSS 9.8 Sep 29, 2025

This vulnerability allows unauthenticated remote attackers to take over administrative control of Vasion Print (formerly PrinterLogic) systems during initial setup. Attackers can exploit a default adm...

CVE-2025-34216

CRITICAL CVSS 9.8 Sep 29, 2025

Vasion Print (formerly PrinterLogic) Virtual Appliance exposes unauthenticated REST API endpoints that leak configuration files, clear-text passwords, and the Laravel APP_KEY. An attacker who obtains ...

CVE-2025-34221

CRITICAL CVSS 9.8 Sep 29, 2025

This vulnerability allows unauthenticated attackers to access all internal Docker containers in Vasion Print (formerly PrinterLogic) deployments, bypassing authentication entirely. Attackers can inter...

CVE-2025-34207

CRITICAL CVSS 9.8 Sep 29, 2025

This vulnerability allows attackers to capture SSH private keys from compromised Docker containers in Vasion Print deployments due to insecure SSH client configuration. The insecure settings disable h...

CVE-2025-34212

CRITICAL CVSS 9.8 Sep 29, 2025

This CVE describes a supply chain vulnerability in Vasion Print (formerly PrinterLogic) build pipeline that allows attackers to compromise the CI/CD system. Attackers can inject malicious firmware or ...

CVE-2025-34196

CRITICAL CVSS 9.8 Sep 29, 2025

Vasion Print (formerly PrinterLogic) contains hardcoded private keys and passwords in configuration files, allowing attackers who obtain these files to impersonate the Certificate Authority, sign mali...

CVE-2025-34203

CRITICAL CVSS 9.8 Sep 19, 2025

Vasion Print (formerly PrinterLogic) contains outdated, end-of-life third-party components across multiple Docker containers, creating a large attack surface. Attackers can chain vulnerabilities in th...

CVE-2025-34205

CRITICAL CVSS 9.8 Sep 19, 2025

This vulnerability allows unauthenticated attackers to reset the database administrator password to a known value ('password') via an exposed PHP script, potentially leading to full database compromis...

CVE-2025-34195

CRITICAL CVSS 9.8 Sep 19, 2025

This vulnerability allows remote code execution on Windows systems running vulnerable versions of Vasion Print (formerly PrinterLogic). Attackers can exploit unquoted program paths during driver insta...

CVE-2025-34198

CRITICAL CVSS 9.8 Sep 19, 2025

Vasion Print (formerly PrinterLogic) appliances use the same hardcoded SSH host private keys across all installations instead of unique per-appliance keys. This allows attackers who obtain these keys ...

CVE-2025-34192

CRITICAL CVSS 9.8 Sep 19, 2025

This vulnerability affects Vasion Print (formerly PrinterLogic) deployments using outdated OpenSSL 1.0.2h-fips, which has been end-of-life since 2019. Attackers could exploit known unpatched vulnerabi...

CVE-2025-34234

HIGH CVSS 7.5 Sep 29, 2025

Vasion Print (formerly PrinterLogic) contains hardcoded encryption keys in its application containers, allowing attackers who can access the filesystem to decrypt sensitive SaaS identifiers. This affe...

CVE-2025-34225

HIGH CVSS 8.6 Sep 29, 2025

This CVE describes an unauthenticated server-side request forgery (SSRF) vulnerability in Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application. Attackers can exploit this to mak...

CVE-2025-34231

HIGH CVSS 8.6 Sep 29, 2025

This CVE describes an unauthenticated server-side request forgery (SSRF) vulnerability in Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application. Attackers can force the server to...

CVE-2025-34202

HIGH CVSS 8.8 Sep 19, 2025

This vulnerability exposes Docker container networks in Vasion Print (formerly PrinterLogic) deployments, allowing attackers on the same network segment to directly access internal services like HTTP ...

CVE-2025-34200

HIGH CVSS 7.8 Sep 19, 2025

Vasion Print (formerly PrinterLogic) Virtual Appliance stores network account credentials in clear-text in the world-readable /etc/issue file. An attacker with local shell access can read these creden...

CVE-2025-34190

HIGH CVSS 7.8 Sep 19, 2025

This vulnerability allows local attackers to bypass authentication in Vasion Print (formerly PrinterLogic) by preloading a malicious shared object that overrides the geteuid() function. This tricks th...

CVE-2025-34194

HIGH CVSS 7.8 Sep 19, 2025

This vulnerability allows local unprivileged users to escalate privileges to SYSTEM level by exploiting insecure temporary file handling in Vasion Print (formerly PrinterLogic). The software creates f...

CVE-2025-34188

HIGH CVSS 7.8 Sep 19, 2025

This vulnerability allows local users to extract authentication session tokens from cleartext log files in Vasion Print (formerly PrinterLogic) deployments. Attackers can use these tokens to authentic...

CVE-2025-34210

MEDIUM CVSS 5.5 Oct 2, 2025

Vasion Print (formerly PrinterLogic) Virtual Appliance stores sensitive credentials in cleartext world-readable files, allowing any local user or process with filesystem access to steal database passw...

CVE-2025-34233

MEDIUM CVSS 6.8 Sep 29, 2025

This vulnerability allows admin-level attackers in Vasion Print (formerly PrinterLogic) to exploit improper input validation in printer configuration fields. By injecting malicious hostnames that redi...

CVE-2025-34229

MEDIUM CVSS 5.8 Sep 29, 2025

This CVE describes a blind server-side request forgery (SSRF) vulnerability in Vasion Print (formerly PrinterLogic) that allows unauthenticated attackers to make HTTP requests from the vulnerable serv...

CVE-2025-34230

MEDIUM CVSS 5.8 Sep 29, 2025

This CVE describes a blind server-side request forgery (SSRF) vulnerability in Vasion Print (formerly PrinterLogic) that allows unauthenticated attackers to make HTTP requests from the vulnerable serv...

CVE-2025-34220

MEDIUM CVSS 5.3 Sep 29, 2025

An unauthenticated API endpoint in Vasion Print (formerly PrinterLogic) allows remote attackers to enumerate all group objects for a tenant. This exposes internal identifiers including group IDs, Azur...

CVE-2025-34211

MEDIUM CVSS 4.9 Sep 29, 2025

Vasion Print (formerly PrinterLogic) appliances contain a hardcoded private SSL key and matching certificate stored in cleartext. This allows attackers with container-level access to decrypt TLS traff...