An issue was discovered in DriveLock 24.1 through 24.1., 24.2 through 24.2., and 25.1 through 25.1.*. An incomplete configuration (agent authentication) in DriveLock tenant allows attackers to impersonate any DriveLock agent on the network against the DES (DriveLock Enterprise Service).
[
{
"events": [
{
"introduced": "24.1"
},
{
"last_affected": "24.1.4"
}
]
},
{
"events": [
{
"introduced": "24.2"
},
{
"last_affected": "24.2.8"
}
]
},
{
"events": [
{
"introduced": "25.1"
},
{
"last_affected": "25.1.6"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-67791.json"