Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.
Conclusion & alert: CVE-2025-32433 is rated Critical Active Threat (99.2/100): CVSS Critical severity, with high exploitation likelihood (EPSS 62.61%, 98th percentile). Core evidence: CISA KEV confirms active exploitation (added 2025-06-09) affecting Erlang / Erlang/OTP. a weakness (CWE-306) Unauthenticated remote administrative access may be possible. Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
: Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability · CISA KEV detail
: 2025-06-09
: 2025-06-30
: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-05 | 62.85% | 62.61% | -0.24% |
| 2 | 2026-06-04 | 59.97% | 62.85% | +2.87% |
| 3 | 2026-06-03 | — | 59.97% | — |
Full EPSS history (86 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 10.0 | 3.1 | CRITICAL |
|
3.9 | 6.0 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
critical | CVE-2025-32433: 1 source package rows (erlang); 1 state rows across 1 repos (3.21-community); fixed 1, open 0. | https://security.alpinelinux.org/vuln/CVE-2025-32433 |
debian
|
not yet assigned | CVE-2025-32433 not yet assigned priority: Debian including 1 source packages (erlang), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2025-32433 |
suse
|
critical | CVE-2025-32433 severity critical: SUSE including 46 source package names (erlang, erlang-22.2.7-150200.3.13.1, …), 92 product×package rows across 23 product lines (SUSE Enterprise Storage 7.1, SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS, … (23 product lines)): Fixed 82, Known Not Affected 10. | https://www.suse.com/security/cve/CVE-2025-32433/ |
ubuntu
|
high | CVE-2025-32433 high priority: Ubuntu including 1 source packages (erlang), 9 status rows across 9 suites (bionic, focal, jammy, noble, oracular, plucky, trusty, upstream, xenial): released 8, not-affected 1. | https://ubuntu.com/security/CVE-2025-32433 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| erlang | erlang\/otp | < 25.3.2.20 | cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:* |
| erlang | erlang\/otp | >= 26.0, < 26.2.5.11 | cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:* |
| erlang | erlang\/otp | >= 27.0, < 27.3.3 | cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:* |
| cisco | confd_basic | < 7.7.19.1 | cpe:2.3:a:cisco:confd_basic:*:*:*:*:*:*:*:* |
| cisco | confd_basic | >= 8.0.18, < 8.1.16.2 | cpe:2.3:a:cisco:confd_basic:*:*:*:*:*:*:*:* |
| cisco | confd_basic | >= 8.2, < 8.2.11.1 | cpe:2.3:a:cisco:confd_basic:*:*:*:*:*:*:*:* |
| cisco | confd_basic | >= 8.3, < 8.3.8.1 | cpe:2.3:a:cisco:confd_basic:*:*:*:*:*:*:*:* |
| cisco | confd_basic | >= 8.4, < 8.4.4.1 | cpe:2.3:a:cisco:confd_basic:*:*:*:*:*:*:*:* |
| cisco | network_services_orchestrator | < 5.7.19.1 | cpe:2.3:a:cisco:network_services_orchestrator:*:*:*:*:*:*:*:* |
| cisco | network_services_orchestrator | >= 5.8, < 6.1.16.2 | cpe:2.3:a:cisco:network_services_orchestrator:*:*:*:*:*:*:*:* |
| cisco | network_services_orchestrator | >= 6.2, < 6.2.11.1 | cpe:2.3:a:cisco:network_services_orchestrator:*:*:*:*:*:*:*:* |
| cisco | network_services_orchestrator | >= 6.3, < 6.3.8.1 | cpe:2.3:a:cisco:network_services_orchestrator:*:*:*:*:*:*:*:* |
| cisco | network_services_orchestrator | >= 6.4, < 6.4.1.1 | cpe:2.3:a:cisco:network_services_orchestrator:*:*:*:*:*:*:*:* |
| cisco | network_services_orchestrator | >= 6.4.2, < 6.4.4.1 | cpe:2.3:a:cisco:network_services_orchestrator:*:*:*:*:*:*:*:* |
| cisco | cloud_native_broadband_network_gateway | < 2025.03.1 | cpe:2.3:a:cisco:cloud_native_broadband_network_gateway:*:*:*:*:*:*:*:* |
| cisco | inode_manager | — | cpe:2.3:a:cisco:inode_manager:-:*:*:*:*:*:*:* |
| cisco | smart_phy | < 25.2 | cpe:2.3:a:cisco:smart_phy:*:*:*:*:*:*:*:* |
| cisco | ultra_packet_core | < 2025.03 | cpe:2.3:a:cisco:ultra_packet_core:*:*:*:*:*:*:*:* |
| cisco | ultra_services_platform | — | cpe:2.3:a:cisco:ultra_services_platform:-:*:*:*:*:*:*:* |
| cisco | staros | < 2025.03 | cpe:2.3:o:cisco:staros:*:*:*:*:*:*:*:* |
| cisco | optical_site_manager | < 25.2.1 | cpe:2.3:a:cisco:optical_site_manager:*:*:*:*:*:*:*:* |
| cisco | ncs_2000_shelf_virtualization_orchestrator_firmware | < 25.1.1 | cpe:2.3:o:cisco:ncs_2000_shelf_virtualization_orchestrator_firmware:*:*:*:*:*:*:*:* |
| cisco | enterprise_nfv_infrastructure_software | < 4.18 | cpe:2.3:a:cisco:enterprise_nfv_infrastructure_software:*:*:*:*:*:*:*:* |
| cisco | ultra_cloud_core | < 2025.03.1 | cpe:2.3:a:cisco:ultra_cloud_core:*:*:*:*:*:*:*:* |
| cisco | rv160w_firmware | — | cpe:2.3:o:cisco:rv160w_firmware:-:*:*:*:*:*:*:* |
| cisco | rv260_firmware | — | cpe:2.3:o:cisco:rv260_firmware:-:*:*:*:*:*:*:* |
| cisco | rv160_firmware | — | cpe:2.3:o:cisco:rv160_firmware:-:*:*:*:*:*:*:* |
| cisco | rv260p_firmware | — | cpe:2.3:o:cisco:rv260p_firmware:-:*:*:*:*:*:*:* |
| cisco | rv260w_firmware | — | cpe:2.3:o:cisco:rv260w_firmware:-:*:*:*:*:*:*:* |
| cisco | rv340_firmware | — | cpe:2.3:o:cisco:rv340_firmware:-:*:*:*:*:*:*:* |
| cisco | rv340w_firmware | — | cpe:2.3:o:cisco:rv340w_firmware:-:*:*:*:*:*:*:* |
| cisco | rv345_firmware | — | cpe:2.3:o:cisco:rv345_firmware:-:*:*:*:*:*:*:* |
| cisco | rv345p_firmware | — | cpe:2.3:o:cisco:rv345p_firmware:-:*:*:*:*:*:*:* |
| debian | debian_linux | 11.0 | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |