PT-2025-51924 · Unknown+1 · Drivelock Enterprise Service+1

Published

2025-12-17

·

Updated

2025-12-21

·

CVE-2025-67791

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DriveLock versions 24.1 through 24.1.* DriveLock versions 24.2 through 24.2.* DriveLock versions 25.1 through 25.1.*
Description An incomplete configuration related to agent authentication in DriveLock tenants can allow attackers to impersonate any DriveLock agent on the network against the DriveLock Enterprise Service (DES). This allows attackers to potentially gain unauthorized access and control within the network.
Recommendations Update DriveLock to a version beyond 25.1.*. Review and correct the DriveLock tenant configuration to ensure proper agent authentication.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-67791

Affected Products

Drivelock
Drivelock Enterprise Service