CVE-2025-32433
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated r...
Affects 37 products across 7 vendors.
Software does not perform any authentication for functionality that requires a verified identity.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A critical vulnerability in the SSH server of Erlang/OTP, a programming language used in various industrial control systems, allows an unauthenticated attacker to execute arbitrary code remotely. Successful exploitation could lead to full control of affected systems, potentially disrupting industrial processes and compromising safety systems. Organizations using affected versions of Erlang/OTP in their OT environments are at significant risk.
BSID: BS-2025-GLOBAL-254014-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2025-32433?
What is the CVSS score for CVE-2025-32433?
Is CVE-2025-32433 actively exploited?
How do I remediate CVE-2025-32433?
What systems are affected by CVE-2025-32433?
What NERC-CIP standard applies to CVE-2025-32433?
What IEC 62443 requirement maps to CVE-2025-32433?
| CVE ID | CVE-2025-32433 |
|---|---|
| BSID | BS-2025-GLOBAL-254014-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Published | 2025-04-16 |
| Last Modified | 2025-11-04 |
| ICS Relevance | 100% |
| Weakness (CWE) | |
| Verticals | |
| Domains | |
| Source | NVD |
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.
Source: NIST NVD / MITRE CVE Database
The vulnerability exists in the SSH server implementation of Erlang/OTP. An unauthenticated attacker can send a specially crafted SSH protocol message to the server, which triggers a flaw in the message handling code. This flaw allows the attacker to execute arbitrary code on the server without needing valid credentials. The attacker must have network access to the SSH server, typically over TCP port 22. Post-exploitation, the attacker gains full control of the affected system, enabling them to manipulate industrial processes, steal sensitive data, or cause physical damage. This is a pre-authentication remote code execution (RCE) vulnerability, making it highly dangerous in OT environments.
Exploitation Likelihood: HIGH
| Vendor | Product | Fixed Version |
|---|---|---|
| Cisco | Rv340 | — |
| Cisco | Ultra Services Platform | — |
| Cisco | Enterprise Nfv Infrastructure Software | — |
| Cisco | Network Services Orchestrator | — |
| Cisco | Ncs 1001 | — |
| Cisco | Ncs 1002 | — |
| Cisco | Ncs 1004 | — |
| Cisco | Rv340W Firmware | — |
| Cisco | Rv340W | — |
| Cisco | Rv340 Firmware | — |
| Cisco | Staros | — |
| Cisco | Rv345 Firmware | — |
| Cisco | Rv345 | — |
| Cisco | Rv345P Firmware | — |
| Cisco | Rv345P | — |
| Cisco | Rv160 Firmware | — |
| Cisco | Rv160 | — |
| Cisco | Rv160W Firmware | — |
| Cisco | Rv160W | — |
| Cisco | Rv260 Firmware | — |
| Cisco | Rv260 | — |
| Cisco | Rv260P Firmware | — |
| Cisco | Rv260P | — |
| Cisco | Rv260W Firmware | — |
| Cisco | Rv260W | — |
| Cisco | Smart Phy | — |
| Cisco | Ultra Cloud Core | — |
| Cisco | Confd Basic | — |
| Cisco | Inode Manager | — |
| Cisco | Cloud Native Broadband Network Gateway | — |
| Cisco | Ultra Packet Core | — |
| Cisco | Optical Site Manager | — |
| Cisco | Ncs 2000 Shelf Virtualization Orchestrator Firmware | — |
| Cisco | Ncs 2000 Shelf Virtualization Orchestrator Module | — |
| Debian | Debian Linux | — |
| Erlang | Erlang/Otp | — |
| Erlang | Erlang\/Otp | — |
| Fujitsu-Siemens | — | — |
| Schneider-Electric | — | — |
| Siemens | — | — |
| Wolfram Schneider | — | — |
| CISA KEV | ● Active Exploitation Confirmed (added 2025-06-09) |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Disable the SSH server on affected systems or restrict access to trusted IP addresses using firewall rules. Implement network segmentation to isolate affected systems from the broader OT network. Ensure that only authorized personnel can access the SSH server. Apply these controls at the Purdue Model Level 2/3 boundary.
No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.
CIP-007-R1 requires the identification and disabling of unnecessary ports and services. The vulnerable SSH server represents an unnecessary service on BES Cyber Assets if remote management is not required.
IEC 62443 SR 3.5 (Input Validation) is directly violated. The SSH server fails to validate the input data correctly, leading to a buffer overflow and potential remote code execution.
Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.
SAGE Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | e6d11302e5dcf3444bddeb9e124b9bdf5672884185c9d87ae59b3a53c259db4daf08b250a8aff76c404cac1df5fcc9455d1570305ec04c468343ea29d3ef1bbe |
This Vulnerability Is Being Actively Exploited
CVE-2025-32433 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider alerts your team within 15 minutes when KEV vulnerabilities match your ICS assets.
Start Free KEV Monitoring →