PT-2025-39885 · Unknown · Vasion Print+1

Pierre Barre

·

Published

2025-09-29

·

Updated

2025-10-02

·

CVE-2025-34220

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Vasion Print versions prior to 25.1.102 Vasion Print Application versions prior to 25.1.1413
Description The /api-gateway/identity/search-groups API endpoint does not require authentication. An unauthenticated remote attacker can enumerate every group object stored for a tenant by sending requests to https://.printercloud10.com/api-gateway/identity/search-groups and adjusting the Host header. The response includes internal identifiers such as group ID, source service ID, Azure AD object IDs, creation timestamps, and tenant IDs.
Recommendations Update Vasion Print to version 25.1.102 or later. Update Vasion Print Application to version 25.1.1413 or later.

Exploit

Fix

Missing Authentication

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-34220

Affected Products

Vasion Print
Vasion Print Application