CRITICAL🇵🇱 Wersja polska

CVE-2025-67787

CVSS 9.6v3.1pub. 2025-12-17upd. 2026-01-02

An issue was discovered in 25.1.2 before 25.1.5. A Cross Site Scripting (XSS) issue in DriveLock Operations Center allows for session takeover over a network.

🤖 AI Analysis
How it works

The XSS class vulnerability (CWE-79) consists of the ability to inject and execute malicious JavaScript code in the context of the victim's browser. The attack vector indicates that user interaction (UI:R) is required to carry out the attack, while the attack originates from a remote location over the network (AV:N) without the need for privileges (PR:N). Due to the changed scope (S:C), the effects of the attack extend beyond the application being the direct target, potentially threatening associated resources.

Impact

An attacker can hijack the session of a logged-in DriveLock Operations Center user, thereby gaining access to system data and functions with the victim's privilege level. Consequences include high loss of data confidentiality and integrity as well as partial threat to system availability.

Mitigation & patch

DriveLock should be updated to version 25.1.5 or newer, in which the bug has been fixed. Details are available in the manufacturer's security bulletin (Security Bulletin 25-002) at the address indicated in the references.

Who is affected

DriveLock in versions from 25.1.2 to 25.1.4 (before version 25.1.5) — DriveLock Operations Center component.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
  • Drivelock

    APP
    Drivelock
    25.1.225.1.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2025-67791CRITICAL9.8PL ✓same product

DriveLock — obejście uwierzytelniania agenta (Auth Bypass) w DES

CVE-2025-67781CRITICAL9.9PL ✓same product

DriveLock — eskalacja uprawnień przez manipulację procesami uprzywilejowanymi

CVE-2025-67793CRITICAL9.8PL ✓same product

DriveLock — nieautoryzowana eskalacja uprawnień do roli Supervisor przez API

CVE-2025-55187CRITICAL9.9PL ✓same product

DriveLock — privilege escalation umożliwiające przejęcie kontroli nad systemem

CVE-2025-67790HIGH7.5same product

An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. An unpriv...