PT-2025-51898 · Drivelock · Drivelock
Published
2025-12-17
·
Updated
2025-12-21
·
CVE-2025-67789
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
DriveLock versions 24.1 through 24.1.5
DriveLock versions 24.2 through 24.2.6
DriveLock versions 25.1 through 25.1.4
Description
An issue exists where authenticated users can obtain the computer count for other DriveLock tenants through the DriveLock API. This is due to insufficient access controls allowing unauthorized information disclosure. The API endpoint allows access to data belonging to other tenants. The vulnerable parameter is not specified.
Recommendations
Update DriveLock to version 24.1.6 or later.
Update DriveLock to version 24.2.7 or later.
Update DriveLock to version 25.1.5 or later.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Drivelock