Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to 22.0.1049 and Application prior to 20.0.2786 (VA and SaaS deployments) configure the SSH client within Docker instances with the following options: `UserKnownHostsFile=/dev/null`, `StrictHostKeyChecking=no`, and `ForwardAgent yes`. These settings disable verification of the remote host’s SSH key and automatically forward the developer’s SSH‑agent to any host that matches the configured wildcard patterns. As a result, an attacker who can reach a single compromised container can cause the container to connect to a malicious SSH server, capture the forwarded private keys, and use those keys for unrestricted lateral movement across the environment. This vulnerability has been identified by the vendor as: V-2024-027 — Insecure Secure Shell (SSH) Configuration.
References
Link | Resource |
---|---|
https://help.printerlogic.com/saas/Print/Security/Security-Bulletins.htm | Vendor Advisory |
https://help.printerlogic.com/va/Print/Security/Security-Bulletins.htm | Vendor Advisory |
https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html#va-insecure-ssh-config | Third Party Advisory |
https://www.vulncheck.com/advisories/vasion-print-printerlogic-insecure-ssh-client-config | Third Party Advisory |
https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html#va-insecure-ssh-config | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
03 Oct 2025, 16:23
Type | Values Removed | Values Added |
---|---|---|
First Time |
Vasion
Vasion virtual Appliance Host Vasion virtual Appliance Application |
|
References | () https://help.printerlogic.com/saas/Print/Security/Security-Bulletins.htm - Vendor Advisory | |
References | () https://help.printerlogic.com/va/Print/Security/Security-Bulletins.htm - Vendor Advisory | |
References | () https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html#va-insecure-ssh-config - Third Party Advisory | |
References | () https://www.vulncheck.com/advisories/vasion-print-printerlogic-insecure-ssh-client-config - Third Party Advisory | |
CPE | cpe:2.3:a:vasion:virtual_appliance_host:*:*:*:*:*:*:*:* cpe:2.3:a:vasion:virtual_appliance_application:*:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
02 Oct 2025, 22:15
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to 22.0.1049 and Application prior to 20.0.2786 (VA and SaaS deployments) configure the SSH client within Docker instances with the following options: `UserKnownHostsFile=/dev/null`, `StrictHostKeyChecking=no`, and `ForwardAgent yes`. These settings disable verification of the remote host’s SSH key and automatically forward the developer’s SSH‑agent to any host that matches the configured wildcard patterns. As a result, an attacker who can reach a single compromised container can cause the container to connect to a malicious SSH server, capture the forwarded private keys, and use those keys for unrestricted lateral movement across the environment. This vulnerability has been identified by the vendor as: V-2024-027 — Insecure Secure Shell (SSH) Configuration. |
30 Sep 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html#va-insecure-ssh-config - |
29 Sep 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-29 21:15
Updated : 2025-10-03 16:23
NVD link : CVE-2025-34207
Mitre link : CVE-2025-34207
CVE.ORG link : CVE-2025-34207
JSON object : View
Products Affected
vasion
- virtual_appliance_application
- virtual_appliance_host