Cyber Posture

CVE-2025-27670

Critical

Published: 05 March 2025

Published
05 March 2025
Modified
01 April 2025
KEV Added
Patch
CVSS Score 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0016 37.0th percentile
Risk Priority 20 60% EPSS · 20% KEV · 20% CVSS

Description

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.

Security Summary

CVE-2025-27670 is an Insufficient Signature Validation vulnerability, identified as OVE-20230524-0014 and mapped to CWE-347 (Improper Authentication), affecting Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.843 Application 20.0.1923. Published on 2025-03-05, it carries a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), marking it as critical due to its potential for severe impact.

Remote attackers require no privileges, authentication, or user interaction to exploit this over the network with low attack complexity. Successful exploitation grants high-impact access to confidentiality, integrity, and availability, enabling outcomes such as arbitrary code execution or full system compromise on affected appliances.

Mitigation guidance is available in PrinterLogic's security bulletin at https://help.printerlogic.com/saas/Print/Security/Security-Bulletins.htm, which details patching to Virtual Appliance Host 22.0.843 Application 20.0.1923 or later to address the signature validation flaw.

Details

CWE(s)
CWE-347

Affected Products

printerlogic
vasion print
≤ 20.0.1923
printerlogic
virtual appliance
≤ 22.0.843

MITRE ATT&CK Enterprise Techniques

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
Why these techniques?

The vulnerability is an unauthenticated remote code execution flaw in a public-facing virtual appliance (insufficient signature validation allowing arbitrary code execution or full compromise), directly enabling T1190 Exploit Public-Facing Application.

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

References