CVE-2025-34221: Vasion Print (formerly PrinterLogic)
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.2.169 and Application prior to version 25.2.1518 (VA/SaaS deployments) expose every internal Docker container to the network because firewall rules allow unrestricted traffic to the Docker bridge network. Because no authentication, ACL or client‑side identifier is required, the attacker can interact with any internal API, bypassing the product’s authentication mechanisms entirely. The result is unauthenticated remote access to internal services, allowing credential theft, configuration manipulation and potential remote code execution. This vulnerability has been identified by the vendor as: V-2025-002 — Authentication Bypass - Docker Instances.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34221?
CVE-2025-34221 is considered a high-severity vulnerability due to the unrestricted network access it allows to internal Docker containers.
How do I fix CVE-2025-34221?
To fix CVE-2025-34221, you should upgrade to Vasion Print Virtual Appliance Host version 25.2.169 or later, and Vasion Print Application version 25.2.1518 or later.
What impact does CVE-2025-34221 have on my network?
CVE-2025-34221 can potentially allow unauthorized access to sensitive information hosted in internal Docker containers, compromising security.
Which versions of Vasion Print are affected by CVE-2025-34221?
Versions prior to 25.2.169 of Vasion Print Virtual Appliance Host and prior to 25.2.1518 of Vasion Print Application are affected by CVE-2025-34221.
Is there a workaround for CVE-2025-34221?
There are no specific workarounds; the best course of action is to upgrade to the recommended versions to mitigate the risk.