216.73.216.233

CVE-2025-34188

· Published 19/09/2025 19:15 · Modified 19/09/2025 19:15

Labels: CVE-2025-34188 2025-09-19CVE-2025-34188CWE-532[email protected]

Essential information

Published
19/09/2025 19:15
Modified
19/09/2025 19:15
Author
Creator
CVSS
8.4 HIGH (v3) 8.4 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application prior to 20.0.1330 (macOS/Linux client deployments) contain a vulnerability in the local logging mechanism. Authentication session tokens, including PHPSESSID, XSRF-TOKEN, and laravel_session, are stored in cleartext within world-readable log files. Any local user with access to the machine can extract these session tokens and use them to authenticate remotely to the SaaS environment, bypassing normal login credentials, potentially leading to unauthorized system access and exposure of sensitive information.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
printerlogic / vation print cpe:2.3:a:printerlogic:vation_print:*:*:*:*:*:*:*:*
printerlogic / vation print cpe:2.3:a:printerlogic:vation_print:1.0.735:*:*:*:*:*:*:*
printerlogic / vation print cpe:2.3:a:printerlogic:vation_print:20.0.1330:*:*:*:*:*:*:*

References