216.73.216.233

CVE-2025-34211

· Published 29/09/2025 21:15 · Modified 30/09/2025 14:15

Labels: CVE-2025-34211 2025-09-29CVE-2025-34211CWE-321[email protected]

Essential information

Published
29/09/2025 21:15
Modified
30/09/2025 14:15
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version 20.0.2786 (VA and SaaS deployments) contain a private SSL key and matching public certificate stored in cleartext. The key belongs to the hostname `pl‑local.com` and is used by the appliance to terminate TLS connections on ports 80/443. Because the key is hardcoded, any attacker who can gain container-level access can simply read the files and obtain the private key. With the private key, the attacker can decrypt TLS traffic, perform man-in-the-middle attacks, or forge TLS certificates. This enables impersonation of the appliance’s web UI, interception of credentials, and unrestricted access to any services that trust the certificate. The same key is identical across all deployed appliances meaning a single theft compromises the confidentiality of every Vasion Print installation.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
vasion print / virtual appliance host cpe:2.3:a:vasion_print:virtual_appliance_host:<22.0.1049:*:*:*:*:*:*:*
vasion print / application cpe:2.3:a:vasion_print:application:<20.0.2786:*:*:*:*:*:*:*

References