drivelock vulnerabilities
CVEs whose affected-version data names the drivelock package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2025-67791Critical· 9.8An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*
An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*. An incomplete configuration (agent authentication) in DriveLock tenant allows attackers to impersonate any DriveLock agent on the net…
▾ Midnightdrivelock · drivelockEPSS 0.37%via NVD
CVE-2025-67787Critical· 9.6An issue was discovered in 25.1.2 before 25.1.5
An issue was discovered in 25.1.2 before 25.1.5. A Cross Site Scripting (XSS) issue in DriveLock Operations Center allows for session takeover over a network.
▾ Midnightdrivelock · drivelockEPSS 0.26%via NVD