CNNVD-202509-3076 Information
CNNVD ID
CNNVD-202509-3076
Related CVE
- CNNVD Published: 2025-09-19
Description (Chinese)
Vasion Print和Vasion Print Virtual Appliance Host都是Vasion公司的产品。Vasion Print是一款基于 SaaS 的云托管应用程序,用于管理和部署打印机。Vasion Print Virtual Appliance Host是一个打印管理软件。 Vasion Print Virtual Appliance Host和Vasion Print Application存在安全漏洞,该漏洞源于网络账户凭据以明文形式存储在/etc/issue文件中且默认全局可读,可能导致本地攻击者获取凭据并修改网络参数。
Description (English)
Vasion Print and Vasion Prince Virgin Application Host are both products of Vasion. Vasion Print is a cloud hosting application based on SaaS for the management and deployment of printers. Vasion Prit Virgin Application Host is a print management software. There is a security loophole in Vasion Print Virgin Application Host and Vasion Prince Application, which stems from the fact that network accounts are stored in explicit form in /etc/issue and are defaulted to be readable in the /etc/issue file, which may lead local attackers to obtain evidence and modify network parameters.
Hazard Level
High
Vulnerability Type
其他
Affected Vendor
Vela
Published
2025-09-19
Last Modified
2026-02-24
References
https://help.printerlogic.com/saas/Print/Security/Security-Bulletins.htm https://help.printerlogic.com/va/Print/Security/Security-Bulletins.htm https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html#va-clear-text-password https://www.vulncheck.com/advisories/vasion-print-printerlogic-network-account-password-stored-in-cleartext https://access.redhat.com/security/cve/cve-2025-34200