Cryptographic exposure via outdated bundled OpenSSL dependency
Published Sep 19, 2025 · Updated Sep 19, 2025
Use of an unmaintained component in Vasion Print deployments allows remote attackers to reach obsolete OpenSSL code through network traffic. The PrinterInstallerClient module bundles OpenSSL 1.0.2h-fips, and its installation script explicitly selects the 1.0.2h release rather than a maintained dependency. Exposure is limited to macOS and Linux client deployments from Application versions before 20.0.2140 or Virtual Appliance Host versions before 22.0.893; no specific exploited OpenSSL flaw is identified.
Summary
What happened
Use of an unmaintained component in Vasion Print deployments allows remote attackers to reach obsolete OpenSSL code through network traffic. The PrinterInstallerClient module bundles OpenSSL 1.0.2h-fips, and its installation script explicitly selects the 1.0.2h release rather than a maintained dependency. Exposure is limited to macOS and Linux client deployments from Application versions before 20.0.2140 or Virtual Appliance Host versions before 22.0.893; no specific exploited OpenSSL flaw is identified.
The record
- CVE
- CVE-2025-34192
- Published
- Sep 19, 2025
- Updated
- Sep 19, 2025
- Vendor
- Vasion
- Product
- Vasion Print Application
- Classifications
- CWE-1104
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Sep 19, 2025CVE publishedPublication date reported by the CVE source.
- Sep 19, 2025Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=* <20.0.2140
What conditions does exploitation require?
What is affected?
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
No public exploit references are available in this record.
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo