CVE-2025-32433

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
16/04/2025
Last modified:
04/11/2025

Description

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:* 25.3.2.20 (excluding)
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:* 26.0 (including) 26.2.5.11 (excluding)
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:* 27.0 (including) 27.3.3 (excluding)
cpe:2.3:a:cisco:confd_basic:*:*:*:*:*:*:*:* 7.7.19.1 (excluding)
cpe:2.3:a:cisco:confd_basic:*:*:*:*:*:*:*:* 8.0.18 (including) 8.1.16.2 (excluding)
cpe:2.3:a:cisco:confd_basic:*:*:*:*:*:*:*:* 8.2 (including) 8.2.11.1 (excluding)
cpe:2.3:a:cisco:confd_basic:*:*:*:*:*:*:*:* 8.3 (including) 8.3.8.1 (excluding)
cpe:2.3:a:cisco:confd_basic:*:*:*:*:*:*:*:* 8.4 (including) 8.4.4.1 (excluding)
cpe:2.3:a:cisco:network_services_orchestrator:*:*:*:*:*:*:*:* 5.7.19.1 (excluding)
cpe:2.3:a:cisco:network_services_orchestrator:*:*:*:*:*:*:*:* 5.8 (including) 6.1.16.2 (excluding)
cpe:2.3:a:cisco:network_services_orchestrator:*:*:*:*:*:*:*:* 6.2 (including) 6.2.11.1 (excluding)
cpe:2.3:a:cisco:network_services_orchestrator:*:*:*:*:*:*:*:* 6.3 (including) 6.3.8.1 (excluding)
cpe:2.3:a:cisco:network_services_orchestrator:*:*:*:*:*:*:*:* 6.4 (including) 6.4.1.1 (excluding)
cpe:2.3:a:cisco:network_services_orchestrator:*:*:*:*:*:*:*:* 6.4.2 (including) 6.4.4.1 (excluding)
cpe:2.3:a:cisco:cloud_native_broadband_network_gateway:*:*:*:*:*:*:*:* 2025.03.1 (excluding)