CyberSec.Space Logo
CVEブラウザに戻る

CVE-2025-32433

🔥 Known Exploited (CISA KEV)CRITICAL
10.0
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2025-04-16
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.

Affected Platforms (CPE)

📦
Erlang

Erlang\/otp

< 25.3.2.20>= 26.0 and < 26.2.5.11>= 27.0 and < 27.3.3
📦
Cisco

Confd Basic

< 7.7.19.1>= 8.0.18 and < 8.1.16.2>= 8.2 and < 8.2.11.1>= 8.3 and < 8.3.8.1>= 8.4 and < 8.4.4.1
📦
Cisco

Network Services Orchestrator

< 5.7.19.1>= 5.8 and < 6.1.16.2>= 6.2 and < 6.2.11.1>= 6.3 and < 6.3.8.1>= 6.4 and < 6.4.1.1>= 6.4.2 and < 6.4.4.1
📦
Cisco

Cloud Native Broadband Network Gateway

< 2025.03.1

References & Advisories

関連するセキュリティ記事

関連する脆弱性情報