CVE-2025-67793
- EPSS 0.31%
- Veröffentlicht 17.12.2025 00:00:00
- Zuletzt bearbeitet 02.01.2026 15:54:36
An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 before 25.1.6. Users with the "Manage roles and permissions" privilege can promote themselves or other DOC users to the Supervisor role through an API call. This ...
CVE-2025-67791
- EPSS 0.38%
- Veröffentlicht 17.12.2025 00:00:00
- Zuletzt bearbeitet 18.12.2025 20:16:08
An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*. An incomplete configuration (agent authentication) in DriveLock tenant allows attackers to impersonate any DriveLock agent on the network against ...
CVE-2025-67794
- EPSS 0.11%
- Veröffentlicht 17.12.2025 00:00:00
- Zuletzt bearbeitet 18.12.2025 20:16:08
An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 before 24.2.8, and 25.1 before 25.1.6. Directories and files created by the agent are created with overly permissive ACLs, allowing local users without administrator rights to trigger act...
CVE-2025-55187
- EPSS 0.42%
- Veröffentlicht 26.09.2025 15:16:03
- Zuletzt bearbeitet 08.10.2025 20:20:03
In DriveLock 24.1.4 before 24.1.5, 24.2.5 before 24.2.6, and 25.1.2 before 25.1.4, attackers can gain elevated privileges.