Vasion Print Insecure Password Hashing Vulnerability

Vulnerability

A vulnerability exists in Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application in VA/SaaS deployments, where user passwords are stored using unsalted SHA-512 hashes, with a fallback to unsalted SHA-1. This hashing is done using PHP's hash() function in several files. The absence of per-user salts and the use of fast hash algorithms unsuitable for password storage leave passwords vulnerable to offline dictionary or rainbow table attacks. Additionally, the code includes logic that upgrades legacy SHA-1 hashes to SHA-512 upon login, further risking users still using the old hash.

Impact

Exploitation of this vulnerability allows for the recovery of cleartext passwords from the hashed password database, using offline dictionary or rainbow table attacks.

Remediation

Users can update to Vasion Print Virtual Appliance Host v22.0.1026 / Application v20.0.2702, where this vulnerability has been fixed.

Added: Oct 2, 2025, 5:24 PM
Updated: Oct 2, 2025, 7:20 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.2
remediation
0.0
relevance
0.6
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.