CVE-2025-34196 (CNNVD-202509-4380)
中文标题:
Vasion Print Virtual Appliance Host 安全漏洞
英文标题:
Vasion Print (formerly PrinterLogic) Hardcoded PrinterLogic CA Private Key and Hardcoded Password
漏洞描述
中文描述:
Vasion Print Virtual Appliance Host是美国Vasion公司的一个打印管理软件。 Vasion Print Virtual Appliance Host 25.1.102之前版本存在安全漏洞,该漏洞源于硬编码私钥和密码,可能导致中间人攻击或冒充攻击。
英文描述:
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application prior to 25.1.1413 (Windows client deployments) contain a hardcoded private key for the PrinterLogic Certificate Authority (CA) and a hardcoded password in product configuration files. The Windows client ships the CA certificate and its associated private key (and other sensitive settings such as a configured password) directly in shipped configuration files (for example clientsettings.dat and defaults.ini). An attacker who obtains these files can impersonate the CA, sign arbitrary certificates trusted by the Windows client, intercept or decrypt TLS-protected communications, and otherwise perform man-in-the-middle or impersonation attacks against the product's network communications. This vulnerability has been identified by the vendor as: V-2022-001 — Configuration File Contains CA & Private Key.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Vasion | Print Virtual Appliance Host | - | < 25.1.102 | - |
cpe:2.3:a:vasion:print_virtual_appliance_host:*:*:*:*:*:*:*:*
|
| Vasion | Print Application | - | < 25.1.1413 | - |
cpe:2.3:a:vasion:print_application:*:*:*:*:*:*:*:*
|
| vasion | virtual_appliance_application | * | - | - |
cpe:2.3:a:vasion:virtual_appliance_application:*:*:*:*:*:*:*:*
|
| vasion | virtual_appliance_host | * | - | - |
cpe:2.3:a:vasion:virtual_appliance_host:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
4.0 (cna)
CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-34196 |
2025-11-11 15:23:17 | 2025-11-11 07:40:25 |
| NVD | nvd_CVE-2025-34196 |
2025-11-11 15:01:04 | 2025-11-11 07:48:15 |
| CNNVD | cnnvd_CNNVD-202509-4380 |
2025-11-11 15:12:59 | 2025-11-11 08:00:14 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-202509-4380
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 2 -> 4
- data_sources: ['cve'] -> ['cve', 'nvd']