CVE-2025-34217

Severity CVSS v4.0:
CRITICAL
Type:
CWE-321 Use of Hard-coded Cryptographic Key
Publication date:
30/09/2025
Last modified:
07/10/2025

Description

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) contain an undocumented 'printerlogic' user with a hardcoded SSH public key in '~/.ssh/authorized_keys' and a sudoers rule granting the printerlogic_ssh group 'NOPASSWD: ALL'. Possession of the matching private key gives an attacker root access to the appliance.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vasion:virtual_appliance_application:-:*:*:*:*:*:*:*
cpe:2.3:a:vasion:virtual_appliance_host:-:*:*:*:*:*:*:*