CVE-2025-34206

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) mount host configuration and secret material under /var/www/efs_storage into many Docker containers with overly-permissive filesystem permissions. Files such as secrets.env, GPG-encrypted blobs in .secrets, MySQL client keys, and application session files are accessible from multiple containers. An attacker who controls or reaches any container can read or modify these artifacts, leading to credential theft, RCE via Laravel APP_KEY, Portainer takeover, and full compromise.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vasion:virtual_appliance_application:-:*:*:*:*:*:*:*
cpe:2.3:a:vasion:virtual_appliance_host:-:*:*:*:*:*:*:*

History

24 Sep 2025, 18:46

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References () https://help.printerlogic.com/saas/Print/Security/Security-Bulletins.htm - () https://help.printerlogic.com/saas/Print/Security/Security-Bulletins.htm - Vendor Advisory
References () https://help.printerlogic.com/va/Print/Security/Security-Bulletins.htm - () https://help.printerlogic.com/va/Print/Security/Security-Bulletins.htm - Vendor Advisory
References () https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html#va-insecure-security-architecture - () https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html#va-insecure-security-architecture - Exploit, Third Party Advisory
References () https://www.vulncheck.com/advisories/vasion-print-printerlogic-insecure-shared-storage-permissions - () https://www.vulncheck.com/advisories/vasion-print-printerlogic-insecure-shared-storage-permissions - Third Party Advisory
CPE cpe:2.3:a:vasion:virtual_appliance_application:-:*:*:*:*:*:*:*
cpe:2.3:a:vasion:virtual_appliance_host:-:*:*:*:*:*:*:*
First Time Vasion virtual Appliance Host
Vasion virtual Appliance Application
Vasion

19 Sep 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-19 19:15

Updated : 2025-09-24 18:46


NVD link : CVE-2025-34206

Mitre link : CVE-2025-34206

CVE.ORG link : CVE-2025-34206


JSON object : View

Products Affected

vasion

  • virtual_appliance_application
  • virtual_appliance_host
CWE
CWE-312

Cleartext Storage of Sensitive Information

CWE-732

Incorrect Permission Assignment for Critical Resource