CVE-2025-32433

● KEV CRITICAL

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated r...

Affects 37 products across 7 vendors.

BCS10.0
CVSS 3.110.0
EPSS98.6%
Percentile100th
PatchPatched
KEV Added2025-06-09
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-306: Missing Authentication for Critical Function

Software does not perform any authentication for functionality that requires a verified identity.

Related Attack Patterns (CAPEC)
CAPEC-12 Choosing Message Identifier
via CWE-306
CAPEC-36 Using Unpublished Interfaces or Functionality
via CWE-306
CAPEC-62 Cross Site Request Forgery
via CWE-306
CAPEC-166 Force the System to Reset Values
via CWE-306
CAPEC-216 Communication Channel Manipulation
via CWE-306

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical vulnerability in the SSH server of Erlang/OTP, a programming language used in various industrial control systems, allows an unauthenticated attacker to execute arbitrary code remotely. Successful exploitation could lead to full control of affected systems, potentially disrupting industrial processes and compromising safety systems. Organizations using affected versions of Erlang/OTP in their OT environments are at significant risk.

BSID: BS-2025-GLOBAL-254014-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2025-32433?
A critical vulnerability in the SSH server of Erlang/OTP, a programming language used in various industrial control systems, allows an unauthenticated attacker to execute arbitrary code remotely. Successful exploitation could lead to full control of affected systems, potentially disrupting industrial processes and compromising safety systems. Organizations using affected versions of Erlang/OTP in their OT environments are at significant risk.
What is the CVSS score for CVE-2025-32433?
CVE-2025-32433 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. EPSS: 98.6%.
Is CVE-2025-32433 actively exploited?
Yes. CVE-2025-32433 is in the CISA KEV catalog (added 2025-06-09). Active exploitation confirmed. Immediate patching required.
How do I remediate CVE-2025-32433?
Priority: IMMEDIATE. Advisory: https://github.com/erlang/otp/commit/0fcd9c56524b28615e8ece65fc0c3f66ef6e4c12 PSIRT: [email protected]
What systems are affected by CVE-2025-32433?
CVE-2025-32433 affects: Cisco, Cisco, Cisco, Cisco, Cisco, Cisco, Cisco, Cisco.
What NERC-CIP standard applies to CVE-2025-32433?
NERC CIP CIP-007 CIP-007-R1: CIP-007-R1 requires the identification and disabling of unnecessary ports and services. The vulnerable SSH server represents an unnecessary service on BES Cyber Assets if remote management is not required.
What IEC 62443 requirement maps to CVE-2025-32433?
IEC 62443 SR 3.5: IEC 62443 SR 3.5 (Input Validation) is directly violated. The SSH server fails to validate the input data correctly, leading to a buffer overflow and potential remote code execution.
Vulnerability Details
CVE IDCVE-2025-32433
BSIDBS-2025-GLOBAL-254014-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published2025-04-16
Last Modified2025-11-04
ICS Relevance100%
Weakness (CWE)
Verticals
ICS-OT
Domains
NETWORK-INFRA
SourceNVD
Official Description

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability exists in the SSH server implementation of Erlang/OTP. An unauthenticated attacker can send a specially crafted SSH protocol message to the server, which triggers a flaw in the message handling code. This flaw allows the attacker to execute arbitrary code on the server without needing valid credentials. The attacker must have network access to the SSH server, typically over TCP port 22. Post-exploitation, the attacker gains full control of the affected system, enabling them to manipulate industrial processes, steal sensitive data, or cause physical damage. This is a pre-authentication remote code execution (RCE) vulnerability, making it highly dangerous in OT environments.

Exploitation Likelihood: HIGH

Affected Products
VendorProductFixed Version
Cisco Rv340
Cisco Ultra Services Platform
Cisco Enterprise Nfv Infrastructure Software
Cisco Network Services Orchestrator
Cisco Ncs 1001
Cisco Ncs 1002
Cisco Ncs 1004
Cisco Rv340W Firmware
Cisco Rv340W
Cisco Rv340 Firmware
Cisco Staros
Cisco Rv345 Firmware
Cisco Rv345
Cisco Rv345P Firmware
Cisco Rv345P
Cisco Rv160 Firmware
Cisco Rv160
Cisco Rv160W Firmware
Cisco Rv160W
Cisco Rv260 Firmware
Cisco Rv260
Cisco Rv260P Firmware
Cisco Rv260P
Cisco Rv260W Firmware
Cisco Rv260W
Cisco Smart Phy
Cisco Ultra Cloud Core
Cisco Confd Basic
Cisco Inode Manager
Cisco Cloud Native Broadband Network Gateway
Cisco Ultra Packet Core
Cisco Optical Site Manager
Cisco Ncs 2000 Shelf Virtualization Orchestrator Firmware
Cisco Ncs 2000 Shelf Virtualization Orchestrator Module
Debian Debian Linux
Erlang Erlang/Otp
Erlang Erlang\/Otp
Fujitsu-Siemens —
Schneider-Electric —
Siemens —
Wolfram Schneider —
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 464 Days
CISA KEV● Active Exploitation Confirmed (added 2025-06-09)
Public ExploitNot confirmed
PoC CodeNot confirmed
● Virtual Patch — CITED Relevance SAGE Engine MEDIUM CONFIDENCE

Disable the SSH server on affected systems or restrict access to trusted IP addresses using firewall rules. Implement network segmentation to isolate affected systems from the broader OT network. Ensure that only authorized personnel can access the SSH server. Apply these controls at the Purdue Model Level 2/3 boundary.

No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.

NERC CIP: CIP-007 CIP-007-R1
CIP-007-R1 requires the identification and disabling of unnecessary ports and services. The vulnerable SSH server represents an unnecessary service on BES Cyber Assets if remote management is not required.
IEC 62443: SR 3.5
IEC 62443 SR 3.5 (Input Validation) is directly violated. The SSH server fails to validate the input data correctly, leading to a buffer overflow and potential remote code execution.

Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.

SAGE Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashe6d11302e5dcf3444bddeb9e124b9bdf5672884185c9d87ae59b3a53c259db4daf08b250a8aff76c404cac1df5fcc9455d1570305ec04c468343ea29d3ef1bbe
Related CVEs affecting Cisco
CVE-2025-20393 10.0 A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for ... CVE-2007-2036 10.0 The SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 200... CVE-2003-0732 10.0 CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the gues... CVE-2004-0308 10.0 Unknown vulnerability in Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(... CVE-2007-5382 10.0 The conversion utility for converting CiscoWorks Wireless LAN Solution Engine...
View all Cisco CVEs →

This Vulnerability Is Being Actively Exploited

CVE-2025-32433 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider alerts your team within 15 minutes when KEV vulnerabilities match your ICS assets.

Start Free KEV Monitoring →