CVE-2025-67791: Drivelock
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*. An incomplete configuration (agent authentication) in DriveLock tenant allows attackers to impersonate any DriveLock agent on the network against the DES (DriveLock Enterprise Service).
Affected products
- Drivelock Drivelock: from 24.1, up to and including 24.1.4; from 24.2, up to and including 24.2.8; from 25.1, up to and including 25.1.6
Published 2025-12-17. Last modified 2026-09-25.