CVE-2025-32433
16.04.2025, 22:15
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.Enginsight
Vendor | Product | Version |
---|---|---|
erlang | erlang\/otp | 𝑥 < 25.3.2.20 |
erlang | erlang\/otp | 26.0 ≤ 𝑥 < 26.2.5.11 |
erlang | erlang\/otp | 27.0 ≤ 𝑥 < 27.3.3 |
cisco | confd_basic | 𝑥 < 7.7.19.1 |
cisco | confd_basic | 8.0.18 ≤ 𝑥 < 8.1.16.2 |
cisco | confd_basic | 8.2 ≤ 𝑥 < 8.2.11.1 |
cisco | confd_basic | 8.3 ≤ 𝑥 < 8.3.8.1 |
cisco | confd_basic | 8.4 ≤ 𝑥 < 8.4.4.1 |
cisco | network_services_orchestrator | 𝑥 < 5.7.19.1 |
cisco | network_services_orchestrator | 5.8 ≤ 𝑥 < 6.1.16.2 |
cisco | network_services_orchestrator | 6.2 ≤ 𝑥 < 6.2.11.1 |
cisco | network_services_orchestrator | 6.3 ≤ 𝑥 < 6.3.8.1 |
cisco | network_services_orchestrator | 6.4 ≤ 𝑥 < 6.4.1.1 |
cisco | network_services_orchestrator | 6.4.2 ≤ 𝑥 < 6.4.4.1 |
cisco | cloud_native_broadband_network_gateway | 𝑥 < 2025.03.1 |
cisco | inode_manager | - |
cisco | smart_phy | 𝑥 < 25.2 |
cisco | ultra_packet_core | - |
cisco | ultra_services_platform | - |
cisco | staros | * |
cisco | optical_site_manager | 𝑥 < 25.2.1 |
cisco | ncs_2000_shelf_virtualization_orchestrator_firmware | 𝑥 < 25.1.1 |
cisco | enterprise_nfv_infrastructure_software | 𝑥 < 4.18 |
cisco | ultra_cloud_core | 𝑥 < 2025.03.1 |
cisco | rv160w_firmware | - |
cisco | rv260_firmware | - |
cisco | rv160_firmware | - |
cisco | rv260p_firmware | - |
cisco | rv260w_firmware | - |
cisco | rv340_firmware | - |
cisco | rv340w_firmware | - |
cisco | rv345_firmware | - |
cisco | rv345p_firmware | - |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
erlang |
|
Common Weakness Enumeration
References