PT-2025-38599 · Vasion · Vasion Print Virtual Appliance

Pierre Barre

·

Published

2025-09-19

·

Updated

2025-09-20

·

CVE-2025-34200

CVSS v4.0

8.6

High

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) (affected versions not specified)
Description The Vasion Print Virtual Appliance exposes network account credentials in clear-text within the /etc/issue file, which is world-readable by default. An attacker gaining local shell access can read this file to obtain the network account username and password. Utilizing these credentials, an attacker can modify network parameters through the appliance interface, potentially leading to local misconfiguration, network disruption, or further escalation depending on the deployment environment.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2025-34200

Affected Products

Vasion Print Virtual Appliance