CVE 9.3 CRITICAL

Vasion Print (formerly PrinterLogic) Insecure Shared Storage Permissions_CVE-2025-34206

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) mount host configuration and secret material under /var/www/efs_storage into many Docker containers with overly-permissive filesystem permissions. Files such as secrets.env, GPG-encrypted blobs in .secrets, MySQL client keys, and application session files are accessible from multiple containers. An attacker who controls or reaches any container can read or modify these artifacts, leading to credential theft, RCE via Laravel APP_KEY, Portainer takeover, and full compromise.

Basic Information

ID CVE-2025-34206
Source VulnCheck
Published Sep 19, 2025 at 18:48

Affected Product

Vendor Vasion
Product Print Virtual Appliance Host
Version *
Affected Versions Vasion Print Virtual Appliance Host *
Vasion Print Application (SaaS/VA) *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.