Beveiligingsadvies

CVE-2025-64348

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-10-31 18:31:21
Laatst bijgewerkt 2025-11-04 15:58:49
Toegewezen door cisa-cg
CVSS-score 9.3
Status PUBLISHED

Beschrijving

ELOG allows an authenticated user to modify or overwrite the configuration file, resulting in denial of service. If the execute facility is specifically enabled with the "-x" command line flag, attackers could execute OS commands on the host machine. By default, ELOG is not configured to allow shell commands or self-registration.