CVE-2025-34210: Vasion Print (formerly PrinterLogic) Readable Cleartext Passwords
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) store a large number of sensitive credentials (database passwords, MySQL root password, SaaS keys, Portainer admin password, etc.) in cleartext files that are world-readable. Any local user - or any process that can read the host filesystem - can retrieve all of these secrets in plain text, leading to credential theft and full compromise of the appliance. The vendor does not consider this to be a security vulnerability as this product "follows a shared responsibility model, where administrators are expected to configure persistent storage encryption."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34210?
CVE-2025-34210 is considered high severity due to the exposure of sensitive credentials in cleartext files.
How do I fix CVE-2025-34210?
To fix CVE-2025-34210, ensure that all sensitive credentials are stored in a secure manner and not in world-readable files.
What types of credentials are exposed in CVE-2025-34210?
CVE-2025-34210 exposes sensitive credentials such as database passwords, MySQL root password, SaaS keys, and Portainer admin password.
Who is affected by CVE-2025-34210?
CVE-2025-34210 affects users of Vasion Print, especially those using Virtual Appliance (VA) or Software as a Service (SaaS) deployments.
What can an attacker do with the information from CVE-2025-34210?
An attacker with access to the exposed credentials in CVE-2025-34210 could potentially gain unauthorized access to the system and compromise sensitive data.