PT-2025-39897 · Vasion · Vasion Print Application+1

Pierre Barre

·

Published

2025-09-29

·

Updated

2025-09-30

·

CVE-2025-34234

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Vasion Print versions prior to 25.1.102 Vasion Print Application versions prior to 25.1.1413
Description Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application deployments contain hardcoded private keys stored in clear text within the application containers (printerlogic/pi, printerlogic/printer-admin-api, and printercloud/pi) under /var/www/app/config/ as keyfile.ppk.dev and keyfile.saasid.ppk.dev. These keys are used as the symmetric secret for AES-256-CBC encryption/decryption of the “SaaS Id” through the getEncryptedExternalId() and getDecryptedExternalId() methods. Access to the Docker image or filesystem allows recovery of the encryption key.
Recommendations Update Vasion Print Virtual Appliance Host to version 25.1.102 or later. Update Vasion Print Application to version 25.1.1413 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-34234

Affected Products

Vasion Print
Vasion Print Application