CVE-2025-34212: Vasion Print (formerly PrinterLogic) Insecure Build Pipeline
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.843 and Application prior to version 20.0.1923 (VA/SaaS deployments) possess CI/CD weaknesses: the build pulls an unverified third-party image, downloads the VirtualBox Extension Pack over plain HTTP without signature validation, and grants the jenkins account NOPASSWD for mount/umount. Together these allow supply chain or man-in-the-middle compromise of the build pipeline, injection of malicious firmware, and remote code execution as root on the CI host. This vulnerability has been identified by the vendor as: V-2023-007 — Supply Chain Attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34212?
The severity of CVE-2025-34212 is moderate due to potential supply chain risks associated with the use of unverified third-party images.
How do I fix CVE-2025-34212?
To fix CVE-2025-34212, upgrade to Vasion Print Virtual Appliance Host version 22.0.843 and Vasion Print Application version 20.0.1923 or later.
What are the potential impacts of CVE-2025-34212?
The potential impacts of CVE-2025-34212 include the risk of exploitation through the usage of unverified third-party components that may compromise system integrity.
Which versions are affected by CVE-2025-34212?
CVE-2025-34212 affects Vasion Print Virtual Appliance Host prior to version 22.0.843 and Vasion Print Application prior to version 20.0.1923.
Is CVE-2025-34212 relevant for all Vasion deployments?
CVE-2025-34212 is specifically relevant for VA/SaaS deployments of Vasion Print software.