CVE-2025-67791

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/12/2025
Last modified:
18/12/2025

Description

An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*. An incomplete configuration (agent authentication) in DriveLock tenant allows attackers to impersonate any DriveLock agent on the network against the DES (DriveLock Enterprise Service).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:drivelock:drivelock:*:*:*:*:*:*:*:* 24.1 (including) 24.1.4 (including)
cpe:2.3:a:drivelock:drivelock:*:*:*:*:*:*:*:* 24.2 (including) 24.2.8 (including)
cpe:2.3:a:drivelock:drivelock:*:*:*:*:*:*:*:* 25.1 (including) 25.1.6 (including)