CVE-2025-34201

HIGH

Vasion Print Virtual Appliance Host - Lateral Movement

Title source: llm
STIX 2.1

Description

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) run many Docker containers on shared internal networks without firewalling or segmentation between instances. A compromise of any single container allows direct access to internal services (HTTP, Redis, MySQL, etc.) on the overlay network. From a compromised container, an attacker can reach and exploit other services, enabling lateral movement, data theft, and system-wide compromise.

Scores

CVSS v3 7.8
EPSS 0.0027
EPSS Percentile 19.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-653
Status published
Products (2)
vasion/virtual_appliance_application
vasion/virtual_appliance_host
Published Sep 19, 2025
Tracked Since Feb 18, 2026