PT-2025-38601 · Laravel+7 · Laravel+7
Pierre Barre
·
Published
2025-09-19
·
Updated
2025-09-20
·
CVE-2025-34203
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.1002
Vasion Print (formerly PrinterLogic) Application versions prior to 20.0.2614
Description
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application deployments contain multiple Docker containers with outdated, end-of-life, unsupported, or vulnerable third-party components, including Nginx 1.17.x, OpenSSL 1.1.1d, and various EOL Alpine/Debian/Ubuntu base images and EOL Laravel/PHP libraries. These components increase the product’s attack surface and can be leveraged in exploitation chains. Nginx binaries date from 2019 in several images, and Laravel versions include EOL releases such as 5.5.x, 5.7.x, and 5.8.x.
Recommendations
Update Vasion Print Virtual Appliance Host to version 22.0.1002 or later.
Update Vasion Print Application to version 20.0.2614 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alpine
Debian
Laravel
Nginx
Openssl
Php
Ubuntu
Vasion Print