CVE-2025-34204

CRITICAL WAF: Low
CVSS 9.8 Published: 2025-09-19
CWE-269

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) contains multiple Docker containers that run primary application processes (for example PHP workers, Node.js servers and custom binaries) as the root user. This increases the blast radius of a container compromise and enables lateral movement and host compromise when a container is breached.

WAF Coverage Analysis

Improper Privilege Management Low WAF Coverage

OWASP: A01:2021 Broken Access Control

Affected Software

VendorProductVersion
vasionvirtual_appliance_application-
vasionvirtual_appliance_host-

References

Back to CVE Database