An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Authenticated users can retrieve the computer count of other DriveLock tenants via the DriveLock API.
References
| Link | Resource |
|---|---|
| https://drivelock.help/versions/current/web/en/releasenotes/Content/ReleaseNotes_DriveLock/SecurityBulletins/25-004-DESInfoDisclosure.htm | Release Notes Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
18 Dec 2025, 19:42
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:drivelock:drivelock:*:*:*:*:*:*:*:* | |
| First Time |
Drivelock
Drivelock drivelock |
|
| References | () https://drivelock.help/versions/current/web/en/releasenotes/Content/ReleaseNotes_DriveLock/SecurityBulletins/25-004-DESInfoDisclosure.htm - Release Notes, Vendor Advisory |
17 Dec 2025, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-17 21:16
Updated : 2025-12-18 19:42
NVD link : CVE-2025-67789
Mitre link : CVE-2025-67789
CVE.ORG link : CVE-2025-67789
JSON object : View
Products Affected
drivelock
- drivelock
CWE
CWE-284
Improper Access Control
