Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to 25.2.169 and Application prior to 25.2.1518 (VA and SaaS deployments) expose Docker internal networks in a way that allows an attacker on the same external L2 segment — or an attacker able to add routes using the appliance as a gateway — to reach container IPs directly. This grants access to internal services (HTTP APIs, Redis, MySQL, etc.) that are intended to be isolated inside the container network. Many of those services are accessible without authentication or are vulnerable to known exploitation chains. As a result, compromise of a single reachable endpoint or basic network access can enable lateral movement, remote code execution, data exfiltration, and full system compromise.
History

Wed, 24 Sep 2025 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Vasion
Vasion virtual Appliance Application
Vasion virtual Appliance Host
CPEs cpe:2.3:a:vasion:virtual_appliance_application:*:*:*:*:*:*:*:*
cpe:2.3:a:vasion:virtual_appliance_host:*:*:*:*:*:*:*:*
Vendors & Products Vasion
Vasion virtual Appliance Application
Vasion virtual Appliance Host
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Mon, 22 Sep 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Printerlogic
Printerlogic vasion Print
Printerlogic virtual Appliance
Vendors & Products Printerlogic
Printerlogic vasion Print
Printerlogic virtual Appliance

Fri, 19 Sep 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 19 Sep 2025 19:00:00 +0000

Type Values Removed Values Added
Description Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to 25.2.169 and Application prior to 25.2.1518 (VA and SaaS deployments) expose Docker internal networks in a way that allows an attacker on the same external L2 segment — or an attacker able to add routes using the appliance as a gateway — to reach container IPs directly. This grants access to internal services (HTTP APIs, Redis, MySQL, etc.) that are intended to be isolated inside the container network. Many of those services are accessible without authentication or are vulnerable to known exploitation chains. As a result, compromise of a single reachable endpoint or basic network access can enable lateral movement, remote code execution, data exfiltration, and full system compromise.
Title Vasion Print (formerly PrinterLogic) Insecure Access to Docker Instances WAN
Weaknesses CWE-291
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-09-19T18:50:09.021Z

Updated: 2025-09-20T03:55:46.761Z

Reserved: 2025-04-15T19:15:22.570Z

Link: CVE-2025-34202

cve-icon Vulnrichment

Updated: 2025-09-19T20:11:22.808Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-19T19:15:41.040

Modified: 2025-09-24T19:19:07.420

Link: CVE-2025-34202

cve-icon Redhat

No data.