CVE-2025-67789

MEDIUM

DriveLock 24.1-24.1.5, 24.2-24.2.6, 25.1-25.1.4 - Authenticated Information Disclosure via API

Title source: llm
STIX 2.1

Description

An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Authenticated users can retrieve the computer count of other DriveLock tenants via the DriveLock API.

Scores

CVSS v3 5.3
EPSS 0.0019
EPSS Percentile 8.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (1)
drivelock/drivelock 24.1 - 24.1.6
Published Dec 17, 2025
Tracked Since Feb 18, 2026