← Back

CVE-2025-32433

Published: Apr 16, 2025Modified: Nov 4, 2025CISA KEV

JSON object

Loading...
10.0
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 6.0
Source: security-advisories@github.com (Secondary)

Description

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.

Affected (34)

1 product
Erlang/otp
21 products
Confd Basic
Network Services Orchestrator
Inode Manager
Smart Phy
Staros
Ultra Packet Core
Ultra Services Platform
Optical Site Manager
Ultra Cloud Core
Rv160w Firmware
Rv260 Firmware
Rv160 Firmware
Rv260p Firmware
Rv260w Firmware
Rv340 Firmware
Rv340w Firmware
Rv345 Firmware
Rv345p Firmware
1 product
Debian Linux
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Erlang
Before 25.3.2.20
From 26.0 to 26.2.5.11
From 27.0 to 27.3.3
Configuration B
5 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Before 7.7.19.1
From 8.0.18 to 8.1.16.2
From 8.2 to 8.2.11.1
From 8.3 to 8.3.8.1
From 8.4 to 8.4.4.1
Configuration C
6 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Before 5.7.19.1
From 5.8 to 6.1.16.2
From 6.2 to 6.2.11.1
From 6.3 to 6.3.8.1
From 6.4 to 6.4.1.1
From 6.4.2 to 6.4.4.1
Configuration D
6 vulnerable
Vulnerable SoftwareAffected Versions
Before 2025.03.1
All versions
Before 25.2
Before 2025.03
Before 2025.03
All versions
Configuration E
1 vulnerable · 3 platform
Vulnerable SoftwareAffected Versions
Before 25.2.1
Running on/withPlatform Versions
Cisco
Ncs 1001
All versions
Cisco
Ncs 1002
All versions
Cisco
Ncs 1004
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 25.1.1
Running on/withPlatform Versions
Cisco
Ncs 2000 Shelf Virtualization Orchestrator Module
All versions
Configuration G
2 vulnerable
Vulnerable SoftwareAffected Versions
Before 4.18
Before 2025.03.1
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Rv160w
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Rv260
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Rv160
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Rv260p
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Rv260w
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Rv340
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Rv340w
All versions
Configuration O
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Rv345
All versions
Configuration P
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Rv345p
All versions
Configuration Q
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.0

References (14)

Source: security-advisories@github.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Exploit
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.