CVE-2025-34200 Details
Description
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) provision the appliance with the network account credentials in clear-text inside /etc/issue, and the file is world-readable by default. An attacker with local shell access can read /etc/issue to obtain the network account username and password. Using the network account an attacker can change network parameters via the appliance interface, enabling local misconfiguration, network disruption or further escalation depending on deployment.
A vulnerability exists in Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application in both VA and SaaS deployments, where network account credentials are stored in cleartext in the /etc/issue file, which is world-readable by default. This allows an attacker with local shell access to read the file and obtain the username and password. With these credentials, the attacker can access the appliance interface to change network parameters, potentially leading to local misconfigurations, network disruptions, or further escalation, depending on the deployment.
Users can update to Vasion Print, Virtual Appliance Host v22.0.1049 / Application v20.0.2786, or later versions. For Vasion Print (formerly PrinterLogic), the Windows Client can be updated to Version 25.0.0.897 or later. If preferred, this update can be pushed via third-party software using the Client installation package available from the Vasion Trust Center.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-312 | Cleartext Storage of Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| vasion virtual appliance application | All versions |
CPE
Remediation
| |
| vasion virtual appliance host | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 24, 2025 | Initial Analysis | [email protected] |
| Sep 19, 2025 | New CVE Received | [email protected] |