CVE-2025-67791

CRITICAL

Drivelock < 24.1.4 - Authentication Bypass

Title source: rule
STIX 2.1

Description

An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*. An incomplete configuration (agent authentication) in DriveLock tenant allows attackers to impersonate any DriveLock agent on the network against the DES (DriveLock Enterprise Service).

Scores

CVSS v3 9.8
EPSS 0.0011
EPSS Percentile 29.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-287
Status published
Products (1)
drivelock/drivelock 24.1 - 24.1.4
Published Dec 17, 2025
Tracked Since Feb 18, 2026