Vasion Print Vulnerable to Outdated Components in Virtual Appliances
CVE-2025-34203

9.3CRITICAL

Key Information:

Vendor

Vasion

Vendor
CVE Published:
19 September 2025

What is CVE-2025-34203?

The Vasion Print Virtual Appliance Host and Application versions before specified thresholds have been identified to harbor multiple Docker containers that rely on outdated and unsupported third-party components. Such components, including legacy versions of Nginx, OpenSSL, and various EOL libraries across multiple container images, contribute to a widened attack surface. Vulnerabilities can potentially be exploited by malicious actors to develop complex exploitation chains. Additionally, the presence of unpatched and end-of-life dependent modules increases the risk exposure for users.

Affected Version(s)

Print Application * < 20.0.2614

Print Virtual Appliance Host * < 22.0.1002

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pierre Barre
.