CVE-2025-67787

9.6

DriveLock · Operations Center

A Cross-Site Scripting (XSS) vulnerability in DriveLock Operations Center allows unauthenticated remote attackers to achieve session takeover.

Executive summary

A critical Cross-Site Scripting vulnerability in DriveLock Operations Center allows unauthenticated attackers to perform session hijacking and gain unauthorized access.

Vulnerability

This is a Cross-Site Scripting (XSS) vulnerability that allows for remote code execution or session manipulation. The vulnerability is exploitable by an unauthenticated attacker, as indicated by the CVSS vector PR:N.

Business impact

Successful exploitation of this vulnerability allows an attacker to hijack user sessions, potentially granting them full administrative control over the DriveLock management console. Given the CVSS score of 9.6, this represents a critical risk of data breach, unauthorized system configuration changes, and severe compromise of internal security policies.

Remediation

Immediate Action: Update DriveLock Operations Center to version 25.1.5 or later as specified in the vendor security bulletin.

Proactive Monitoring: Review web server and application logs for suspicious URL parameters containing script tags or encoded payloads.

Compensating Controls: Deploy a Web Application Firewall (WAF) with strict XSS filtering rules to inspect incoming traffic and block malicious script injection attempts.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a significant risk to organizational infrastructure due to the potential for administrative account takeover. Administrators must prioritize updating the DriveLock Operations Center to the patched version 25.1.5 immediately to prevent potential exploitation.

More DriveLock CVEs