PT-2025-38609 · Unknown · Vasion Print Virtual Appliance+1
Pierre Barre
·
Published
2025-09-19
·
Updated
2025-09-20
·
CVE-2025-34202
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Vasion Print Virtual Appliance Host versions prior to 25.2.169
Vasion Print Application versions prior to 25.2.1518
Description
The Vasion Print Virtual Appliance and Application expose Docker internal networks, allowing attackers on the same external Layer 2 segment, or those able to add routes using the appliance as a gateway, to directly access container IP addresses. This grants access to internal services, including HTTP APIs, Redis, and MySQL, which may lack authentication or are susceptible to known exploitation methods. Successful exploitation can lead to lateral movement, remote code execution, data exfiltration, and full system compromise.
Recommendations
Update Vasion Print Virtual Appliance Host to version 25.2.169 or later.
Update Vasion Print Application to version 25.2.1518 or later.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vasion Print Application
Vasion Print Virtual Appliance