CVE-2025-67787
9.6DriveLock · Operations Center
A Cross-Site Scripting (XSS) vulnerability in DriveLock Operations Center allows unauthenticated remote attackers to achieve session takeover.
Executive summary
A critical Cross-Site Scripting vulnerability in DriveLock Operations Center allows unauthenticated attackers to perform session hijacking and gain unauthorized access.
Vulnerability
This is a Cross-Site Scripting (XSS) vulnerability that allows for remote code execution or session manipulation. The vulnerability is exploitable by an unauthenticated attacker, as indicated by the CVSS vector PR:N.
Business impact
Successful exploitation of this vulnerability allows an attacker to hijack user sessions, potentially granting them full administrative control over the DriveLock management console. Given the CVSS score of 9.6, this represents a critical risk of data breach, unauthorized system configuration changes, and severe compromise of internal security policies.
Remediation
Immediate Action: Update DriveLock Operations Center to version 25.1.5 or later as specified in the vendor security bulletin.
Proactive Monitoring: Review web server and application logs for suspicious URL parameters containing script tags or encoded payloads.
Compensating Controls: Deploy a Web Application Firewall (WAF) with strict XSS filtering rules to inspect incoming traffic and block malicious script injection attempts.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability presents a significant risk to organizational infrastructure due to the potential for administrative account takeover. Administrators must prioritize updating the DriveLock Operations Center to the patched version 25.1.5 immediately to prevent potential exploitation.