An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*. An incomplete configuration (agent authentication) in DriveLock tenant allows attackers to impersonate any DriveLock agent on the network against the DES (DriveLock Enterprise Service).
Metrics
Affected Vendors & Products
References
History
Thu, 18 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-287 | |
| Metrics |
ssvc
|
Thu, 18 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:drivelock:drivelock:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Thu, 18 Dec 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Drivelock
Drivelock drivelock |
|
| Vendors & Products |
Drivelock
Drivelock drivelock |
Wed, 17 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*. An incomplete configuration (agent authentication) in DriveLock tenant allows attackers to impersonate any DriveLock agent on the network against the DES (DriveLock Enterprise Service). | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-18T19:52:55.631Z
Reserved: 2025-12-12T00:00:00.000Z
Link: CVE-2025-67791
Updated: 2025-12-18T19:43:33.454Z
Status : Modified
Published: 2025-12-17T22:15:59.917
Modified: 2025-12-18T20:16:08.340
Link: CVE-2025-67791
No data.
OpenCVE Enrichment
Updated: 2025-12-18T09:57:18Z