CVE-2025-34207
29.09.2025, 21:15
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to 22.0.1049 and Application prior to 20.0.2786 (VA and SaaS deployments)configure the SSH client within Docker instances with the following options: `UserKnownHostsFile=/dev/null`, `StrictHostKeyChecking=no`, and `ForwardAgent yes`. These settings disable verification of the remote hosts SSH key and automatically forward the developers SSHagent to any host that matches the configured wildcard patterns. As a result, an attacker who can reach a single compromised container can cause the container to connect to a malicious SSH server, capture the forwarded private keys, and use those keys for unrestricted lateral movement across the environment.This vulnerability has been identified by the vendor as: V-2024-027 Insecure Secure Shell (SSH) Configuration.Enginsight
| Vendor | Product | Version |
|---|---|---|
| vasion | virtual_appliance_application | 𝑥 < 20.0.2786 |
| vasion | virtual_appliance_host | 𝑥 < 22.0.1049 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References