CVE-2025-32433
Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 30 June 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.
- CVSS 3.1
- 10.0 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 98.75% probability · 100th percentile
- CISA KEV
- Listed 9 June 2025 · due 30 June 2025
- Weakness
- CWE-306
- Affected
- erlang/erlang\/otp · cisco/confd basic · cisco/network services orchestrator · cisco/cloud native broadband network gateway · cisco/inode manager · cisco/smart phy · cisco/ultra packet core · cisco/ultra services platform · cisco/staros · cisco/optical site manager · cisco/ncs 2000 shelf virtualization orchestrator firmware · cisco/enterprise nfv infrastructure software · cisco/ultra cloud core · cisco/rv160w firmware · cisco/rv260 firmware · cisco/rv160 firmware · cisco/rv260p firmware · cisco/rv260w firmware · cisco/rv340 firmware · cisco/rv340w firmware · +3 more
- Source
- security-advisories@github.com
CISA notes
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. This vulnerability affects a common open-source project, third-party library, or a protocol used by different products. For more information, please see: https://github.com/erlang/otp/security/advisories/GHSA-37cp-fgq5-7wc2 ; https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-erlang-otp-ssh-xyZZy ; https://nvd.nist.gov/vuln/detail/CVE-2025-32433
References
- https://github.com/erlang/otp/commit/0fcd9c56524b28615e8ece65fc0c3f66ef6e4c12Patch
- https://github.com/erlang/otp/commit/6eef04130afc8b0ccb63c9a0d8650209cf54892fPatch
- https://github.com/erlang/otp/commit/b1924d37fd83c070055beb115d5d6a6a9490b891Patch
- https://github.com/erlang/otp/security/advisories/GHSA-37cp-fgq5-7wc2Vendor Advisory
- http://www.openwall.com/lists/oss-security/2025/04/16/2Mailing List
- http://www.openwall.com/lists/oss-security/2025/04/18/1Mailing List
- http://www.openwall.com/lists/oss-security/2025/04/18/2Mailing List
- http://www.openwall.com/lists/oss-security/2025/04/18/6Mailing List
- http://www.openwall.com/lists/oss-security/2025/04/19/1Mailing List
- https://lists.debian.org/debian-lts-announce/2025/04/msg00028.htmlThird Party Advisory
- https://security.netapp.com/advisory/ntap-20250425-0001/Third Party Advisory
- https://github.com/ProDefense/CVE-2025-32433/blob/main/CVE-2025-32433.pyExploit
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-erlang-otp-ssh-xyZZyThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-32433US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.