Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.
CVSS
No CVSS.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
Configuration 11 (hide)
AND |
|
Configuration 12 (hide)
AND |
|
Configuration 13 (hide)
AND |
|
Configuration 14 (hide)
AND |
|
Configuration 15 (hide)
AND |
|
Configuration 16 (hide)
AND |
|
History
30 Jul 2025, 19:24
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:cisco:ultra_packet_core:*:*:*:*:*:*:*:* | |
References | () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-erlang-otp-ssh-xyZZy - Third Party Advisory |
30 Jul 2025, 02:17
Type | Values Removed | Values Added |
---|---|---|
References |
|
12 Jun 2025, 16:05
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:h:cisco:rv160:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:rv340:-:*:*:*:*:*:*:* cpe:2.3:a:cisco:enterprise_nfv_infrastructure_software:*:*:*:*:*:*:*:* cpe:2.3:a:cisco:confd_basic:*:*:*:*:*:*:*:* cpe:2.3:h:cisco:rv345:-:*:*:*:*:*:*:* cpe:2.3:a:cisco:optical_site_manager:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:rv160_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:cisco:rv260w_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ncs_1002:-:*:*:*:*:*:*:* cpe:2.3:a:cisco:inode_manager:-:*:*:*:*:*:*:* cpe:2.3:o:cisco:rv260p_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:cisco:rv260_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:cisco:rv160w_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:rv260:-:*:*:*:*:*:*:* cpe:2.3:a:cisco:network_services_orchestrator:*:*:*:*:*:*:*:* cpe:2.3:h:cisco:rv340w:-:*:*:*:*:*:*:* cpe:2.3:o:cisco:rv345p_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:cisco:staros:*:*:*:*:*:*:*:* cpe:2.3:h:cisco:rv160w:-:*:*:*:*:*:*:* cpe:2.3:a:cisco:ultra_cloud_core:*:*:*:*:*:*:*:* cpe:2.3:a:cisco:cloud_native_broadband_network_gateway:*:*:*:*:*:*:*:* cpe:2.3:a:cisco:ultra_packet_core:-:*:*:*:*:*:*:* cpe:2.3:a:cisco:ultra_services_platform:-:*:*:*:*:*:*:* cpe:2.3:a:cisco:smart_phy:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:rv340w_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:cisco:rv340_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ncs_1004:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ncs_2000_shelf_virtualization_orchestrator_module:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:rv260p:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ncs_1001:-:*:*:*:*:*:*:* cpe:2.3:o:cisco:ncs_2000_shelf_virtualization_orchestrator_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cisco:rv345_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:rv260w:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:rv345p:-:*:*:*:*:*:*:* |
|
First Time |
Cisco ncs 1002
Cisco rv160w Cisco ultra Cloud Core Cisco rv260w Cisco rv160w Firmware Cisco ncs 2000 Shelf Virtualization Orchestrator Firmware Cisco confd Basic Cisco rv260p Firmware Cisco smart Phy Cisco rv340w Firmware Cisco rv260 Firmware Cisco Cisco rv345 Firmware Cisco rv260p Cisco rv260 Cisco ultra Packet Core Cisco rv345p Firmware Cisco enterprise Nfv Infrastructure Software Cisco rv345p Cisco rv160 Firmware Cisco optical Site Manager Cisco ultra Services Platform Cisco inode Manager Cisco ncs 1004 Cisco cloud Native Broadband Network Gateway Cisco rv345 Cisco rv160 Cisco rv340 Firmware Cisco rv340 Cisco staros Cisco ncs 1001 Cisco rv340w Cisco network Services Orchestrator Cisco ncs 2000 Shelf Virtualization Orchestrator Module Cisco rv260w Firmware |
11 Jun 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
First Time |
Erlang erlang\/otp
Erlang |
|
CPE | cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:* | |
References | () https://github.com/erlang/otp/security/advisories/GHSA-37cp-fgq5-7wc2 - Vendor Advisory | |
References | () https://github.com/ProDefense/CVE-2025-32433/blob/main/CVE-2025-32433.py - Exploit | |
References | () http://www.openwall.com/lists/oss-security/2025/04/19/1 - Mailing List | |
References | () https://github.com/erlang/otp/commit/0fcd9c56524b28615e8ece65fc0c3f66ef6e4c12 - Patch | |
References | () https://github.com/erlang/otp/commit/6eef04130afc8b0ccb63c9a0d8650209cf54892f - Patch | |
References | () https://github.com/erlang/otp/commit/b1924d37fd83c070055beb115d5d6a6a9490b891 - Patch | |
References | () http://www.openwall.com/lists/oss-security/2025/04/18/1 - Mailing List | |
References | () http://www.openwall.com/lists/oss-security/2025/04/18/6 - Mailing List | |
References | () https://security.netapp.com/advisory/ntap-20250425-0001/ - Third Party Advisory | |
References | () http://www.openwall.com/lists/oss-security/2025/04/18/2 - Mailing List | |
References | () http://www.openwall.com/lists/oss-security/2025/04/16/2 - Mailing List |
25 Apr 2025, 23:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
21 Apr 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
19 Apr 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
19 Apr 2025, 02:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
18 Apr 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
18 Apr 2025, 05:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
CWE |
16 Apr 2025, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-16 22:15
Updated : 2025-07-30 19:24
NVD link : CVE-2025-32433
Mitre link : CVE-2025-32433
JSON object : View
Products Affected
cisco
- rv345p_firmware
- rv160w
- network_services_orchestrator
- ncs_2000_shelf_virtualization_orchestrator_firmware
- rv260_firmware
- ncs_1001
- rv260w_firmware
- rv345
- rv260p_firmware
- ultra_cloud_core
- rv160
- rv340
- optical_site_manager
- enterprise_nfv_infrastructure_software
- inode_manager
- ultra_packet_core
- ncs_1004
- rv345_firmware
- rv160_firmware
- rv340w
- ultra_services_platform
- rv160w_firmware
- ncs_1002
- rv260
- rv260w
- rv345p
- staros
- rv340_firmware
- cloud_native_broadband_network_gateway
- confd_basic
- smart_phy
- rv260p
- rv340w_firmware
- ncs_2000_shelf_virtualization_orchestrator_module
erlang
- erlang\/otp
CWE
No CWE.