CVE-2025-34202
Last modified
CVE-2025-34202 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to 25.2.169 and Application prior to 25.2.1518 (VA and SaaS deployments) expose Docker internal networks in a way that allows an attacker on the same external L2 segment — or an attacker able to add routes using the appliance as a gateway — to reach container IPs directly. This grants access to internal services (HTTP APIs, Redis, MySQL, etc.) that are intended to be isolated inside the container network. EPSS estimates a 0.92% chance of exploitation in the next 30 days.
Description
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to 25.2.169 and Application prior to 25.2.1518 (VA and SaaS deployments) expose Docker internal networks in a way that allows an attacker on the same external L2 segment — or an attacker able to add routes using the appliance as a gateway — to reach container IPs directly. This grants access to internal services (HTTP APIs, Redis, MySQL, etc.) that are intended to be isolated inside the container network. Many of those services are accessible without authentication or are vulnerable to known exploitation chains. As a result, compromise of a single reachable endpoint or basic network access can enable lateral movement, remote code execution, data exfiltration, and full system compromise. This vulnerability has been identified by the vendor as: V-2025-003 — Insecure Access to Docker Instance from WAN.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vasion | Virtual Appliance Application | < 25.1.1413 |
| Vasion | Virtual Appliance Host | < 25.2.169 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-34202?
How severe is CVE-2025-34202?
How do I fix CVE-2025-34202?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-34196Vasion Print (formerly PrinterLogic) Virtual Appliance Host …9.8
- CVE-2025-34197Vasion Print (formerly PrinterLogic) Virtual Appliance Host …7.8
- CVE-2025-34198Vasion Print (formerly PrinterLogic) Virtual Appliance Host …9.8
- CVE-2025-34199Vasion Print (formerly PrinterLogic) Virtual Appliance Host …8.1
- CVE-2025-34200Vasion Print (formerly PrinterLogic) Virtual Appliance Host …7.8
- CVE-2025-34201Vasion Print (formerly PrinterLogic) Virtual Appliance Host …7.8
- CVE-2025-34203Vasion Print (formerly PrinterLogic) Virtual Appliance Host …9.8
- CVE-2025-34204Vasion Print (formerly PrinterLogic) Virtual Appliance Host …9.8
- CVE-2025-34205Vasion Print (formerly PrinterLogic) Virtual Appliance Host …9.8
- CVE-2025-34206Vasion Print (formerly PrinterLogic) Virtual Appliance Host …9.8
- CVE-2025-34207Vasion Print (formerly PrinterLogic) Virtual Appliance Host …9.8
- CVE-2025-34208Vasion Print (formerly PrinterLogic) Virtual Appliance Host …7.5
Are you affected by CVE-2025-34202?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
