Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) mount host configuration and secret material under /var/www/efs_storage into many Docker containers with overly-permissive filesystem permissions. Files such as secrets.env, GPG-encrypted blobs in .secrets, MySQL client keys, and application session files are accessible from multiple containers. An attacker who controls or reaches any container can read or modify these artifacts, leading to credential theft, RCE via Laravel APP_KEY, Portainer takeover, and full compromise.
Metrics
Affected Vendors & Products
References
History
Wed, 24 Sep 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Vasion
Vasion virtual Appliance Application Vasion virtual Appliance Host |
|
CPEs | cpe:2.3:a:vasion:virtual_appliance_application:-:*:*:*:*:*:*:* cpe:2.3:a:vasion:virtual_appliance_host:-:*:*:*:*:*:*:* |
|
Vendors & Products |
Vasion
Vasion virtual Appliance Application Vasion virtual Appliance Host |
|
Metrics |
cvssV3_1
|
Mon, 22 Sep 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Printerlogic
Printerlogic vasion Print Printerlogic virtual Appliance |
|
Vendors & Products |
Printerlogic
Printerlogic vasion Print Printerlogic virtual Appliance |
Fri, 19 Sep 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 19 Sep 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) mount host configuration and secret material under /var/www/efs_storage into many Docker containers with overly-permissive filesystem permissions. Files such as secrets.env, GPG-encrypted blobs in .secrets, MySQL client keys, and application session files are accessible from multiple containers. An attacker who controls or reaches any container can read or modify these artifacts, leading to credential theft, RCE via Laravel APP_KEY, Portainer takeover, and full compromise. | |
Title | Vasion Print (formerly PrinterLogic) Insecure Shared Storage Permissions | |
Weaknesses | CWE-312 CWE-732 |
|
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-09-19T18:48:58.217Z
Updated: 2025-09-19T20:10:07.038Z
Reserved: 2025-04-15T19:15:22.571Z
Link: CVE-2025-34206

Updated: 2025-09-19T20:09:59.393Z

Status : Analyzed
Published: 2025-09-19T19:15:41.623
Modified: 2025-09-24T18:46:15.250
Link: CVE-2025-34206

No data.