Vasion Virtual Appliance存在13個高風險資安漏洞,請儘速確認並進行修補

一、漏洞簡述

研究人員發現 Vasion Virtual Appliance 存在 13 個高風險資安漏洞
類型包含使用硬刻之帳號通行碼、未管控之檔案上傳、未驗證之 API 及未授權之存取等,
請儘速確認並進行修補。


二、設備/版本影響

  • Virtual Appliance Host 25.2.169(不含)以前版本

  • Virtual Appliance Application 25.2.1518(不含)以前版本


三、建議處置(原文複製)

更新 Vasion Print Virtual Appliance Host 至 25.2.169(含)以後版本
更新 Vasion Print Virtual Appliance Application 至 25.2.1518(含)以後版本


四、相關連結

CVE 編號:
CVE-2025-34196
CVE-2025-34209
CVE-2025-34211
CVE-2025-34215
CVE-2025-34216
CVE-2025-34217
CVE-2025-34218
CVE-2025-34221
CVE-2025-34222
CVE-2025-34223
CVE-2025-34224
CVE-2025-34234
CVE-2025-34235

參考資料:

  1. https://nvd.nist.gov/vuln/detail/CVE-2025-34196

  2. https://nvd.nist.gov/vuln/detail/CVE-2025-34209

  3. https://nvd.nist.gov/vuln/detail/CVE-2025-34211

  4. https://nvd.nist.gov/vuln/detail/CVE-2025-34215

  5. https://nvd.nist.gov/vuln/detail/CVE-2025-34216

  6. https://nvd.nist.gov/vuln/detail/CVE-2025-34217

  7. https://nvd.nist.gov/vuln/detail/CVE-2025-34218

  8. https://nvd.nist.gov/vuln/detail/CVE-2025-34221

  9. https://nvd.nist.gov/vuln/detail/CVE-2025-34222

  10. https://nvd.nist.gov/vuln/detail/CVE-2025-34223

  11. https://nvd.nist.gov/vuln/detail/CVE-2025-34224

  12. https://nvd.nist.gov/vuln/detail/CVE-2025-34234

  13. https://nvd.nist.gov/vuln/detail/CVE-2025-34235