CVE-2025-34210 Details
Description
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) store a large number of sensitive credentials (database passwords, MySQL root password, SaaS keys, Portainer admin password, etc.) in cleartext files that are world-readable. Any local user - or any process that can read the host filesystem - can retrieve all of these secrets in plain text, leading to credential theft and full compromise of the appliance. The vendor does not consider this to be a security vulnerability as this product "follows a shared responsibility model, where administrators are expected to configure persistent storage encryption."
A vulnerability exists in Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application in VA/SaaS deployments, where sensitive credentials such as database passwords, MySQL root passwords, SaaS keys, and Portainer admin passwords are stored in cleartext files that are world-readable. This exposure allows any local user or process with access to the host filesystem to retrieve these secrets, leading to credential theft and a full compromise of the appliance. The vendor does not acknowledge this as a security vulnerability, stating that administrators are expected to manage persistent storage encryption.
Users are advised to update to Vasion Print, Virtual Appliance Host v22.0.1049 / Application v20.0.2786, or to Vasion Print, Virtual Appliance Host v22.0.1026 / Application v20.0.2702.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 2, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html#va-readable-passwords | CISA-ADP | ExploitThird Party Advisory |
| https://help.printerlogic.com/saas/Print/Security/Security-Bulletins.htm | [email protected] | Vendor Advisory |
| https://help.printerlogic.com/va/Print/Security/Security-Bulletins.htm | [email protected] | Vendor Advisory |
| https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html#va-readable-passwords | [email protected] | ExploitThird Party Advisory |
| https://www.vulncheck.com/advisories/vasion-print-printerlogic-readble-cleartext-passwords | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-256 | Plaintext Storage of a Password | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| vasion virtual appliance application | All versions |
CPE
Remediation
| |
| vasion virtual appliance host | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 9, 2025 | Initial Analysis | [email protected] |
| Oct 2, 2025 | CVE Modified | CISA-ADP |
| Oct 2, 2025 | New CVE Received | [email protected] |