Unauthenticated Access Vulnerability in Vasion Print Virtual Appliance by PrinterLogic
CVE-2025-34220
Key Information:
- Vendor
Vasion
- Vendor
- CVE Published:
- 29 September 2025
What is CVE-2025-34220?
The Vasion Print (formerly PrinterLogic) Virtual Appliance and Application have a significant vulnerability that allows an unauthenticated remote attacker to interact with the /api-gateway/identity/search-groups endpoint without requiring credentials. By sending requests to the specified URL and manipulating the Host header, attackers can enumerate all group objects associated with a tenant. This includes sensitive information such as internal identifiers like group IDs, Azure AD object IDs, timestamps, and tenant IDs. Although this issue has been reportedly remediated, the exact date when the patch was implemented remains ambiguous.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Print Application * < 25.1.1413
Print Virtual Appliance Host * < 25.1.102
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
