CVE-2025-34217: Vasion Print (formerly PrinterLogic) Undocumented Hardcoded SSH Key
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) contain an undocumented 'printerlogic' user with a hardcoded SSH public key in '~/.ssh/authorizedkeys' and a sudoers rule granting the printerlogicssh group 'NOPASSWD: ALL'. Possession of the matching private key gives an attacker root access to the appliance.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34217?
The severity of CVE-2025-34217 is high due to the potential for unauthorized access through a hardcoded SSH key.
How do I fix CVE-2025-34217?
To fix CVE-2025-34217, remove the undocumented 'printerlogic' user and the hardcoded SSH public key from the authorized_keys file.
What are the implications of CVE-2025-34217?
CVE-2025-34217 allows attackers to gain root access without a password, posing a significant security risk.
Which versions of Vasion Print are affected by CVE-2025-34217?
CVE-2025-34217 affects all versions of Vasion Print that include the undocumented 'printerlogic' user.
Is there a way to mitigate CVE-2025-34217 without a full fix?
Temporary mitigation for CVE-2025-34217 can include disabling SSH access for the 'printerlogic' user.