CVE-2025-27645: Critical severity Vasion Print vulnerability
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Insecure Extension Installation by Trusting HTTP Permission Methods on the Server Side V-2024-005.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Vasion Print (formerly PrinterLogic) / Virtual Appliance Host / Applicationto a version that resolves this vulnerability.Fixed in Virtual Appliance Host 22.0.933Patch V-2024-005
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27645?
CVE-2025-27645 is categorized as a high-severity vulnerability due to its potential for exploitation through insecure extension installations.
How do I fix CVE-2025-27645?
To fix CVE-2025-27645, upgrade to Vasion Print version 22.0.933 or later and Vasion Application version 20.0.2369 or higher.
What type of attack can exploit CVE-2025-27645?
CVE-2025-27645 can be exploited through arbitrary code execution due to insecure extension installation methods.
Which versions are affected by CVE-2025-27645?
CVE-2025-27645 affects Vasion Print versions before 22.0.933 and Vasion Application versions before 20.0.2368.
Can CVE-2025-27645 lead to data breaches?
Yes, CVE-2025-27645 can lead to data breaches if an attacker successfully exploits the vulnerability to install malicious extensions.