CRITICAL · 10.0

CVE-2025-32433

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remo...

Vulnerability Description

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.

CVSS Score

10.0

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ErlangErlang\/Otp< 25.3.2.20
CiscoConfd Basic< 7.7.19.1
CiscoNetwork Services Orchestrator< 5.7.19.1
CiscoCloud Native Broadband Network Gateway< 2025.03.1
CiscoInode Manager-
CiscoSmart Phy< 25.2
CiscoUltra Packet Core< 2025.03
CiscoUltra Services Platform-
CiscoStaros< 2025.03
CiscoOptical Site Manager< 25.2.1
CiscoNcs 1001-
CiscoNcs 1002-
CiscoNcs 1004-
CiscoNcs 2000 Shelf Virtualization Orchestrator Firmware< 25.1.1
CiscoNcs 2000 Shelf Virtualization Orchestrator Module-
CiscoEnterprise Nfv Infrastructure Software< 4.18
CiscoUltra Cloud Core< 2025.03.1
CiscoRv160W Firmware-
CiscoRv160W-
CiscoRv260 Firmware-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-32433?

CVE-2025-32433 is a vulnerability with a CVSS score of 10.0 (CRITICAL). Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remo...

How severe is CVE-2025-32433?

CVE-2025-32433 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2025-32433?

Check the references section above for vendor advisories and patch information. Affected products include: Erlang Erlang\/Otp, Cisco Confd Basic, Cisco Network Services Orchestrator, Cisco Cloud Native Broadband Network Gateway, Cisco Inode Manager.