CVE-2025-34221·Docker vulnerability
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.2.169 and Application prior to version 25.2.1518 (VA/SaaS deployments) expose every internal Docker container to the network because firewall rules allow unrestricted traffic to the Docker bridge network. Because no authentication, ACL or client‑side identifier is required, the attacker can interact with any internal API, bypassing the product’s authentication mechanisms entirely. The result is unauthenticated remote access to internal services, allowing credential theft, configuration manipulation and potential remote code execution. This vulnerability has been identified by the vendor as: V-2025-002 — Authentication Bypass - Docker Instances.
- Severity
- critical
- Software
- Docker
- Fixed in
- 25.2.169
- Published
- 2025-09-29
Affected versions
Until: 25.2.169
Fixed in: 25.2.169
How to fix this CVE
Upgrade Docker to version 25.2.169 or later to patch the Docker bridge network firewall misconfiguration that allows unauthenticated access to internal containers. This critical vulnerability bypasses authentication entirely by exposing internal APIs through unrestricted network access. Apply the update immediately across all affected systems and verify firewall rules are properly configured to restrict Docker bridge access.
sudo dnf update docker-ceDefensia detects this vulnerability
How to check if you are affected
- Step 1: Run `docker --version` or `docker -v` to check your installed Docker version and confirm if it is below 25.2.169
- Step 2: Execute `sudo iptables -L -n -v | grep -i docker` to review current firewall rules on the Docker bridge interface (docker0) and check for unrestricted access rules
- Step 3: Search Docker daemon logs with `sudo journalctl -u docker -n 500 --no-pager | grep -i 'bridge\|network\|unauthorized'` for signs of unusual internal API access attempts
- Step 4: After patching, run `docker --version` again and verify the version is 25.2.169 or higher, then confirm Docker daemon has restarted with `sudo systemctl status docker`
FAQ
What is CVE-2025-34221?
CVE-2025-34221 is a critical authentication bypass flaw in Docker where misconfigured firewall rules expose internal Docker containers to network access without requiring credentials, allowing attackers to interact with internal APIs, steal credentials, and execute arbitrary code.
Is CVE-2025-34221 being actively exploited?
According to CISA's Known Exploited Vulnerabilities (KEV) list, CVE-2025-34221 is not currently being actively exploited in the wild, and no public exploits are available yet.
What versions of Docker are affected by CVE-2025-34221?
All Docker versions prior to 25.2.169 are vulnerable. The exact lower bound of affected versions is unknown, but Docker 25.2.169 and all later versions contain the necessary firewall rule fixes.
How do I check if my server is vulnerable to CVE-2025-34221?
Run `docker --version` to check your version number. If the output shows a version lower than 25.2.169, your system is vulnerable. Additionally, run `sudo iptables -L -n -v | grep docker` to inspect Docker bridge firewall rules and verify they are restrictive rather than permissive.
Does Defensia detect CVE-2025-34221?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Docker is installed on a monitored server, CVE-2025-34221 will appear in your dashboard with remediation steps.
Related Docker CVEs
References
- https://help.printerlogic.com/saas/Print/Security/Security-Bulletins.htm
- https://help.printerlogic.com/va/Print/Security/Security-Bulletins.htm
- https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html#va-auth-bypass
- https://www.vulncheck.com/advisories/vasion-print-printerlogic-unrestriced-access-to-docker-bridge-network
- https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html#va-auth-bypass
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-34221. Free for 1 server.
Get started free