Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2025-34210 Details

Description

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) store a large number of sensitive credentials (database passwords, MySQL root password, SaaS keys, Portainer admin password, etc.) in cleartext files that are world-readable. Any local user - or any process that can read the host filesystem - can retrieve all of these secrets in plain text, leading to credential theft and full compromise of the appliance. The vendor does not consider this to be a security vulnerability as this product "follows a shared responsibility model, where administrators are expected to configure persistent storage encryption."

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-256Plaintext Storage of a Password[email protected]

Affected Products

ProductVersions
vasion virtual appliance application
All versions

CPE

  • cpe:2.3:a:vasion:virtual_appliance_application:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
vasion virtual appliance host
All versions

CPE

  • cpe:2.3:a:vasion:virtual_appliance_host:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

5 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2025-34210
NVD Published Date:
Oct 2, 2025
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2025-34210 Details - Not Deferred