CVE-2025-67789

An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Authenticated users can retrieve the computer count of other DriveLock tenants via the DriveLock API.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:drivelock:drivelock:*:*:*:*:*:*:*:*
cpe:2.3:a:drivelock:drivelock:*:*:*:*:*:*:*:*
cpe:2.3:a:drivelock:drivelock:*:*:*:*:*:*:*:*

History

18 Dec 2025, 19:42

Type Values Removed Values Added
CPE cpe:2.3:a:drivelock:drivelock:*:*:*:*:*:*:*:*
First Time Drivelock
Drivelock drivelock
References () https://drivelock.help/versions/current/web/en/releasenotes/Content/ReleaseNotes_DriveLock/SecurityBulletins/25-004-DESInfoDisclosure.htm - () https://drivelock.help/versions/current/web/en/releasenotes/Content/ReleaseNotes_DriveLock/SecurityBulletins/25-004-DESInfoDisclosure.htm - Release Notes, Vendor Advisory

17 Dec 2025, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-17 21:16

Updated : 2025-12-18 19:42


NVD link : CVE-2025-67789

Mitre link : CVE-2025-67789

CVE.ORG link : CVE-2025-67789


JSON object : View

Products Affected

drivelock

  • drivelock
CWE
CWE-284

Improper Access Control