Insecure SSH Client Configuration in Vasion Print Virtual Appliance by PrinterLogic
CVE-2025-34207

7.9HIGH

Key Information:

Vendor

Vasion

Vendor
CVE Published:
29 September 2025

What is CVE-2025-34207?

The Vasion Print Virtual Appliance and its associated application versions prior to 22.0.1049 and 20.0.2786, respectively, exhibit an insecure SSH client configuration within Docker instances. Key options like 'UserKnownHostsFile=/dev/null', 'StrictHostKeyChecking=no', and 'ForwardAgent yes' are enabled, which compromises the verification process of remote host SSH keys. This configuration allows an attacker to exploit a single compromised container to connect with a malicious SSH server. Consequently, attackers can capture forwarded private keys, enabling them to move laterally and potentially gain unauthorized access across the network environment.

Affected Version(s)

Print Application * < 20.0.2786

Print Virtual Appliance Host * < 22.0.1049

References

CVSS V4

Score:
7.9
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pierre Barre
.
CVE-2025-34207 : Insecure SSH Client Configuration in Vasion Print Virtual Appliance by PrinterLogic