PT-2025-51898 · Drivelock · Drivelock

Published

2025-12-17

·

Updated

2025-12-21

·

CVE-2025-67789

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions DriveLock versions 24.1 through 24.1.5 DriveLock versions 24.2 through 24.2.6 DriveLock versions 25.1 through 25.1.4
Description An issue exists where authenticated users can obtain the computer count for other DriveLock tenants through the DriveLock API. This is due to insufficient access controls allowing unauthorized information disclosure. The API endpoint allows access to data belonging to other tenants. The vulnerable parameter is not specified.
Recommendations Update DriveLock to version 24.1.6 or later. Update DriveLock to version 24.2.7 or later. Update DriveLock to version 25.1.5 or later.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-67789

Affected Products

Drivelock