{"id":"CVE-2025-64348","summary":"ELOG configuration file authorization bypass","details":"ELOG allows an authenticated user to modify or overwrite the configuration file, resulting in denial of service. If the execute facility is specifically enabled with the \"-x\" command line flag, attackers could execute OS commands on the host machine. By default, ELOG is not configured to allow shell commands or self-registration.","modified":"2026-08-12T15:14:34.859491Z","published":"2025-10-31T18:31:21.412Z","database_specific":{"cna_assigner":"cisa-cg","cwe_ids":["CWE-862"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/64xxx/CVE-2025-64348.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"*"},{"last_affected":"*"}]}]},"references":[{"type":"WEB","url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-304-01.json"},{"type":"WEB","url":"https://www.cve.org/CVERecord?id=CVE-2025-64348"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/64xxx/CVE-2025-64348.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-64348"},{"type":"FIX","url":"https://bitbucket.org/ritt/elog/commits/7092ff64f6eb9521f8cc8c52272a020bf3730946"},{"type":"FIX","url":"https://bitbucket.org/ritt/elog/commits/f81e5695c40997322fe2713bfdeba459d9de09dc"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://bitbucket.org/ritt/elog","events":[{"introduced":"0"},{"fixed":"7092ff64f6eb9521f8cc8c52272a020bf3730946"},{"fixed":"f81e5695c40997322fe2713bfdeba459d9de09dc"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"14890967926415446365279283811554730167","length":4153},"id":"CVE-2025-64348-0eeb3258","signature_type":"Function","signature_version":"v1","source":"https://bitbucket.org/ritt/elog@f81e5695c40997322fe2713bfdeba459d9de09dc","target":{"file":"src/elogd.cxx","function":"show_selection_page"}},{"deprecated":false,"digest":{"function_hash":"191464238056371309188494075133006798233","length":22256},"id":"CVE-2025-64348-10b6e62c","signature_type":"Function","signature_version":"v1","source":"https://bitbucket.org/ritt/elog@f81e5695c40997322fe2713bfdeba459d9de09dc","target":{"function":"submit_elog","file":"src/elogd.cxx"}},{"target":{"file":"src/elogd.cxx","function":"send_file_direct"},"deprecated":false,"digest":{"function_hash":"156508049226024249159389416716576295209","length":3154},"id":"CVE-2025-64348-21ae7266","signature_type":"Function","signature_version":"v1","source":"https://bitbucket.org/ritt/elog@f81e5695c40997322fe2713bfdeba459d9de09dc"},{"deprecated":false,"digest":{"length":30751,"function_hash":"27869281459234486031082520637529106373"},"id":"CVE-2025-64348-352731e8","signature_type":"Function","signature_version":"v1","source":"https://bitbucket.org/ritt/elog@f81e5695c40997322fe2713bfdeba459d9de09dc","target":{"file":"src/elogd.cxx","function":"interprete"}},{"target":{"function":"show_edit_form","file":"src/elogd.cxx"},"deprecated":false,"digest":{"function_hash":"269217789594272232662992342993778262939","length":86296},"id":"CVE-2025-64348-3cda8a0c","signature_type":"Function","signature_version":"v1","source":"https://bitbucket.org/ritt/elog@f81e5695c40997322fe2713bfdeba459d9de09dc"},{"signature_type":"Line","signature_version":"v1","source":"https://bitbucket.org/ritt/elog@f81e5695c40997322fe2713bfdeba459d9de09dc","target":{"file":"src/elogd.cxx"},"deprecated":false,"digest":{"line_hashes":["162633968947116360487918579034479957026","49664975703192455022699842635716302851","38599206607862832822399113789461682455","203368497579435317504893229367284672046","41422647768115247549096670213112889433","309220462470475496523607360501612829631","169151933148310755161506287318738645677","182340065290860660652837084765538968521","33521038623497315851739333623789717347","111551238131845473293949641237174060716","178096170532246570225491302282145482537","258626281896510429646113398678000264151","252173568392219059778949788512448958739","197675376302998910614060407610530221380","48066313943854072649116046440414223549","124548968657606105692789406961522940900","173433090796755949568392065326162232127","232033927219033953260721128518968361139","101345995272839674749030212921061796146","337209307936589950750095128429163832088","151855992037434183121283822360662547791","102169321526934687760120882181483425403","274765330842410335169672381920216778308","124522920770561703509365071179698631876","300276095163579481034563838615585727349","102169321526934687760120882181483425403","274765330842410335169672381920216778308","124522920770561703509365071179698631876","7456090232647262277371735292033903978","300241652388757093403777568857490600533","291426619874055112502047184357443776632","212097996318782274646544680326685646092","218312225683759987411847062200196080894","102169321526934687760120882181483425403","274765330842410335169672381920216778308","124522920770561703509365071179698631876","338540597659776140016147000039566101833","300241652388757093403777568857490600533","291426619874055112502047184357443776632","212097996318782274646544680326685646092","336755334193498038561486568584594438319","300241652388757093403777568857490600533","291426619874055112502047184357443776632","212097996318782274646544680326685646092","178478776091677922410893998276452328633","114412825514251237101770879108832796239","7553123818342898360874508328745266915","313939109454401067467706292851907218054","251749819194632143653129899876101672326","280045265471732707126158941591839210446","7553123818342898360874508328745266915","294198151272860058546290820962114299026","301879882104136830358189754333562959240","220531954334670050216064071371002888528","267192410717750757999833029613847876503","146493410142131868493351852478673185796","181491404103925647325840977446388119167","145924339542860173830692550345077543892","255746592901938675096779638397048479521","53258840624591843185091362715092563894","249272103990799151614782992908344242792","126510346941646301855261436506749676573","59703903083644005491918638648426890072","309357292061599744323649287922555363012","219555915744797258828401642405432773968","83492100227414102190001730966158519240","154122804619182651594837900518792138248","263184539612383783736585806549141561737","236293560807209300004330931695391459831","98849401369250239340675555670281991263","172984033018199453021396601882123044399","245473999108791982285384375490626402953","1687654747237139834452229220359588507","98849401369250239340675555670281991263","172984033018199453021396601882123044399","326627604589390108092097793313991661539","1687654747237139834452229220359588507","98849401369250239340675555670281991263","172984033018199453021396601882123044399","201820943339756863764141954596276819539","237902317276461898481543971090710462454","59510642237386083301532087882156932741","86465376627566888910956693039714819984","265668438767834465467257625094297333011","291426619874055112502047184357443776632","212097996318782274646544680326685646092","20350447662876873797171603615331366950","159397204381234155457790642873791434479","258312135234766948677876782548416767","264024904859984910598131170880159446553","277471740249724321354018197928108446552","63203612691536724118321828686388890262","338261629204872574830686763168600086530","326511862303180001132538219336183978424","72951062155723098509690179975540341174","68490212379909719128965936975369913953","332756889154679084316923332541298759652","263606945028308574960094346410644100161","292994649790338643001565124910327403028"],"threshold":0.9},"id":"CVE-2025-64348-a6d29e8f"},{"target":{"file":"src/elogd.cxx","function":"show_elog_entry"},"deprecated":false,"digest":{"function_hash":"275422028516192074359451138099288241971","length":32753},"id":"CVE-2025-64348-cd15a9b9","signature_type":"Function","signature_version":"v1","source":"https://bitbucket.org/ritt/elog@f81e5695c40997322fe2713bfdeba459d9de09dc"},{"signature_version":"v1","source":"https://bitbucket.org/ritt/elog@f81e5695c40997322fe2713bfdeba459d9de09dc","target":{"file":"src/elogd.cxx","function":"process_http_request"},"deprecated":false,"digest":{"function_hash":"178218806764697086513937655539898862932","length":15834},"id":"CVE-2025-64348-f7884793","signature_type":"Function"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-64348.json","vanir_signatures_modified":"2026-08-12T15:14:34Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/MPR:N/MSC:H/MSI:H/MSA:H"}]}