Vulnerability in Vasion Print Virtual Appliance Exposes Internal Docker Networks
CVE-2025-34202

8.7HIGH

Key Information:

Vendor

Vasion

Vendor
CVE Published:
19 September 2025

What is CVE-2025-34202?

The Vasion Print Virtual Appliance and Application expose Docker internal networks, allowing potential attackers on the same external L2 segment to directly access container IPs. This vulnerability permits interaction with internal services such as HTTP APIs, Redis, and MySQL, many of which lack authentication or have known exploitation paths. Consequently, exploitation of a single accessible endpoint can facilitate lateral movement, remote code execution, data exfiltration, and full system compromise.

Affected Version(s)

Print Application * < 20.0.278625.2.1518

Print Virtual Appliance Host * < 25.2.169

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pierre Barre
.
CVE-2025-34202 : Vulnerability in Vasion Print Virtual Appliance Exposes Internal Docker Networks