10.0
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 6.0
Source: security-advisories@github.com (Secondary)
Description
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.
Affected (34)
Products: Erlang: Erlang/otp · Cisco: Confd Basic, Network Services Orchestrator, Cloud Native Broadband Network Gateway, Inode Manager, Smart Phy, Staros, Ultra Packet Core, Ultra Services Platform, Optical Site Manager, Ncs 2000 Shelf Virtualization Orchestrator Firmware, Enterprise Nfv Infrastructure Software, Ultra Cloud Core, Rv160w Firmware, Rv260 Firmware, Rv160 Firmware, Rv260p Firmware, Rv260w Firmware, Rv340 Firmware, Rv340w Firmware, Rv345 Firmware, Rv345p Firmware · Debian: Debian Linux
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 25.3.2.20 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.7.19.1 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.7.19.1 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2025.03.1 | |
| All versions | |
| Before 25.2 | |
| Before 2025.03 | |
| Before 2025.03 | |
| All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 25.2.1 |
| Running on/with | Platform Versions |
|---|---|
Cisco Ncs 1001 | All versions |
Cisco Ncs 1002 | All versions |
Cisco Ncs 1004 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 25.1.1 |
| Running on/with | Platform Versions |
|---|---|
Cisco Ncs 2000 Shelf Virtualization Orchestrator Module | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.18 | |
| Before 2025.03.1 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Rv160w | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Rv260 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Rv160 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Rv260p | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Rv260w | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Rv340 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Rv340w | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Rv345 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Rv345p | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.0 |
References (14)
Source: security-advisories@github.com
Patch
Source: security-advisories@github.com
Patch
Source: security-advisories@github.com
Patch
Source: security-advisories@github.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Exploit
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Third Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Timeline
No history available yet.