Home

Description

An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*. An incomplete configuration (agent authentication) in DriveLock tenant allows attackers to impersonate any DriveLock agent on the network against the DES (DriveLock Enterprise Service).

PUBLISHED Reserved 2025-12-12 | Published 2025-12-17 | Updated 2025-12-18 | Assigner mitre

References

drivelock.help/.../SecurityBulletins/25-006-DESMisconfig.htm

cve.org (CVE-2025-67791)

nvd.nist.gov (CVE-2025-67791)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.