cbcvebase.
CVE-2025-32433
published 2025-04-16

CVE-2025-32433: Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an…

critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
KEVEXPLOIT
CISA Known Exploited Vulnerabilitydue 2025-06-30
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocloud_native_broadband_network_gateway< 2025.03.12025.03.1
ciscoconfd_basic< 7.7.19.17.7.19.1
ciscoconfd_basic>= 8.0.18 < 8.1.16.28.1.16.2
ciscoconfd_basic>= 8.2 < 8.2.11.18.2.11.1
ciscoconfd_basic>= 8.3 < 8.3.8.18.3.8.1
ciscoconfd_basic>= 8.4 < 8.4.4.18.4.4.1
ciscoenterprise_nfv_infrastructure_software< 4.184.18
cisconcs_2000_shelf_virtualization_orchestrator_firmware< 25.1.125.1.1
cisconetwork_services_orchestrator< 5.7.19.15.7.19.1
cisconetwork_services_orchestrator>= 5.8 < 6.1.16.26.1.16.2
cisconetwork_services_orchestrator>= 6.2 < 6.2.11.16.2.11.1
cisconetwork_services_orchestrator>= 6.3 < 6.3.8.16.3.8.1
cisconetwork_services_orchestrator>= 6.4 < 6.4.1.16.4.1.1
cisconetwork_services_orchestrator>= 6.4.2 < 6.4.4.16.4.4.1
ciscooptical_site_manager< 25.2.125.2.1
ciscoproducts_unauthenticated
ciscosmart_phy< 25.225.2
ciscostaros< 2025.032025.03
ciscoultra_cloud_core< 2025.03.12025.03.1
ciscoultra_packet_core< 2025.032025.03
debiandebian_linux
debianerlang< erlang 1:25.2.3+dfsg-1+deb12u1 (bookworm)erlang 1:25.2.3+dfsg-1+deb12u1 (bookworm)
erlangerlang_otp< 25.3.2.2025.3.2.20
erlangerlang_otp>= 0 < 1:23.2.6+dfsg-1+deb11u21:23.2.6+dfsg-1+deb11u2
erlangerlang_otp>= 0 < 1:25.2.3+dfsg-1+deb12u11:25.2.3+dfsg-1+deb12u1

CVSS provenance

nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
osv10.0CRITICAL
vulncheck10.0CRITICAL
cisa10.0CRITICAL