CVE-2025-32433
⚡ CISA KEVPublished: —Modified: —Vendor: ErlangProduct: Erlang/OTP
—
CVSS v3
97.7%
EPSS
⚡ Added to KEV on 2025-06-09 · Federal agencies must remediate by 2025-06-30
Erlang Erlang/OTP SSH server contains a missing authentication for critical function vulnerability. This could allow an attacker to execute arbitrary commands without valid credentials, potentially leading to unauthenticated remote code execution (RCE). By exploiting a flaw in how SSH protocol messages are handled, a malicious actor could gain unauthorized access to affected systems. This vulnerability could affect various products that implement Erlang/OTP SSH server, including—but not limited to—Cisco, NetApp, and SUSE.
💣 Public Exploits0
From Exploit-DB
No public exploits in Exploit-DB.
🔍 Sigma Detection Rules0
Rules tagged with this CVE
No Sigma rules tagged with this CVE.
🛠️ Patch Details7
Affected/fixed versions from threat intel reports
| Erlang OTP SSH server | source ↗ | ||
| Erlang OTP | OTP-27: prior to 27.3.3 OTP-26: prior to 26.2.5.11 OTP-25: prior to 25.3.2.20 | 27.3.3 , 26.2.5.11 , or 25.3.2.20 | source ↗ |
| Schneider Electric Galaxy VXL | — | — | source ↗ |
| Schneider Electric Galaxy VL | — | — | source ↗ |
| Schneider Electric Galaxy VS | — | — | source ↗ |
| Cisco Erlang/OTP SSH Server | source ↗ | ||
| Erlang OTP SSH | OTP < 27.3.3, OTP < 26.2.5.11, OTP < 25.3.2.20 | OTP-27.3.3, OTP-26.2.5.11, OTP-25.3.2.20 | source ↗ |
📰 Threat Intel Coverage5
Digest reports mentioning this CVE
| No Manners Here: The Ruthless Rise of The Gentlemen Ransomware | unit42 | 2026-07-10 |
| Actively Exploited Vulnerability in Erlang/OTP SSH Daemon | hawkeye | 2025-08-15 |
| Multiple Vulnerabilities in Schneider Electric Products | hawkeye | 2025-05-16 |
| Critical Vulnerabilities in Cisco Products | hawkeye | 2025-05-09 |
| The Bug Report - April 2025 Edition | trellix | 2025-05-08 |
📎 References0
No reference URLs.