CVE-2025-32433
Last modified
CVE-2025-32433 is a critical-severity vulnerability rated 10/10 on the CVSS scale. Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). CISA has confirmed active exploitation in the wild. EPSS estimates a 97.67% chance of exploitation in the next 30 days.
Description
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Erlang | Erlang\/Otp | < 25.3.2.20 |
| Erlang | Erlang\/Otp | >= 26.0, < 26.2.5.11 |
| Erlang | Erlang\/Otp | >= 27.0, < 27.3.3 |
| Cisco | Confd Basic | < 7.7.19.1 |
| Cisco | Confd Basic | >= 8.0.18, < 8.1.16.2 |
| Cisco | Confd Basic | >= 8.2, < 8.2.11.1 |
| Cisco | Confd Basic | >= 8.3, < 8.3.8.1 |
| Cisco | Confd Basic | >= 8.4, < 8.4.4.1 |
| Cisco | Network Services Orchestrator | < 5.7.19.1 |
| Cisco | Network Services Orchestrator | >= 5.8, < 6.1.16.2 |
| Cisco | Network Services Orchestrator | >= 6.2, < 6.2.11.1 |
| Cisco | Network Services Orchestrator | >= 6.3, < 6.3.8.1 |
| Cisco | Network Services Orchestrator | >= 6.4, < 6.4.1.1 |
| Cisco | Network Services Orchestrator | >= 6.4.2, < 6.4.4.1 |
| Cisco | Cloud Native Broadband Network Gateway | < 2025.03.1 |
| Cisco | Inode Manager | All versions |
| Cisco | Smart Phy | < 25.2 |
| Cisco | Ultra Packet Core | < 2025.03 |
| Cisco | Ultra Services Platform | All versions |
| Cisco | Staros | < 2025.03 |
| Cisco | Optical Site Manager | < 25.2.1 |
| Cisco | Ncs 2000 Shelf Virtualization Orchestrator Firmware | < 25.1.1 |
| Cisco | Enterprise Nfv Infrastructure Software | < 4.18 |
| Cisco | Ultra Cloud Core | < 2025.03.1 |
| Cisco | Rv160w Firmware | All versions |
| Cisco | Rv260 Firmware | All versions |
| Cisco | Rv160 Firmware | All versions |
| Cisco | Rv260p Firmware | All versions |
| Cisco | Rv260w Firmware | All versions |
| Cisco | Rv340 Firmware | All versions |
| Cisco | Rv340w Firmware | All versions |
| Cisco | Rv345 Firmware | All versions |
| Cisco | Rv345p Firmware | All versions |
| Debian | Debian Linux | 11.0 |
References
- https://lists.debian.org/debian-lts-announce/2025/04/msg00028.htmlThird Party Advisory
- https://security.netapp.com/advisory/ntap-20250425-0001/Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-32433US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-32433?
How severe is CVE-2025-32433?
How do I fix CVE-2025-32433?
Are you affected by CVE-2025-32433?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
