CVE-2025-34211 (CNNVD-202509-4355)
中文标题:
Vasion Print Virtual Appliance Host 安全漏洞
英文标题:
Vasion Print (formerly PrinterLogic) Hardcoded SSL Certificate and Private Keys
漏洞描述
中文描述:
Vasion Print Virtual Appliance Host是美国Vasion公司的一个打印管理软件。 Vasion Print Virtual Appliance Host 22.0.1049之前版本存在安全漏洞,该漏洞源于私钥和公钥证书以明文存储,可能导致中间人攻击和凭据拦截。
英文描述:
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version 20.0.2786 (VA and SaaS deployments) contain a private SSL key and matching public certificate stored in cleartext. The key belongs to the hostname `pl‑local.com` and is used by the appliance to terminate TLS connections on ports 80/443. Because the key is hardcoded, any attacker who can gain container-level access can simply read the files and obtain the private key. With the private key, the attacker can decrypt TLS traffic, perform man-in-the-middle attacks, or forge TLS certificates. This enables impersonation of the appliance’s web UI, interception of credentials, and unrestricted access to any services that trust the certificate. The same key is identical across all deployed appliances meaning a single theft compromises the confidentiality of every Vasion Print installation. This vulnerability has been identified by the vendor as: V-2024-025 — Hardcoded SSL Certificate & Private Keys.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Vasion | Print Virtual Appliance Host | - | < 22.0.1049 | - |
cpe:2.3:a:vasion:print_virtual_appliance_host:*:*:*:*:*:*:*:*
|
| Vasion | Print Application | - | < 20.0.2786 | - |
cpe:2.3:a:vasion:print_application:*:*:*:*:*:*:*:*
|
| vasion | virtual_appliance_application | * | - | - |
cpe:2.3:a:vasion:virtual_appliance_application:*:*:*:*:*:*:*:*
|
| vasion | virtual_appliance_host | * | - | - |
cpe:2.3:a:vasion:virtual_appliance_host:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
4.0 (cna)
CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-34211 |
2025-11-11 15:23:17 | 2025-11-11 07:40:25 |
| NVD | nvd_CVE-2025-34211 |
2025-11-11 15:01:04 | 2025-11-11 07:48:15 |
| CNNVD | cnnvd_CNNVD-202509-4355 |
2025-11-11 15:12:59 | 2025-11-11 08:00:14 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-202509-4355
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 2 -> 4
- data_sources: ['cve'] -> ['cve', 'nvd']