Undocumented SSH User Vulnerability in Vasion Print Virtual Appliance
CVE-2025-34217

10CRITICAL

Key Information:

Vendor

Vasion

Vendor
CVE Published:
30 September 2025

What is CVE-2025-34217?

The Vasion Print Virtual Appliance contains a critical vulnerability arising from an undocumented 'printerlogic' user account with a hardcoded SSH public key present in the '~/.ssh/authorized_keys' file. This security flaw is compounded by a sudoers rule that allows members of the 'printerlogic_ssh' group to execute any command without a password. If an attacker gains access to the associated private key, they could obtain root access to the appliance, potentially compromising sensitive information and system integrity.

Affected Version(s)

Print Application *

Print Virtual Appliance Host *

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pierre Barre
.
CVE-2025-34217 : Undocumented SSH User Vulnerability in Vasion Print Virtual Appliance