← לוח פגיעויות

CVE-2025-32433

קריטית 10.0 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

תיאור (מקור, אנגלית)

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.

מדדים

CVSS 3.1
10.0 (CRITICAL) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS — סבירות ניצול
99% (אחוזון 100) נכון ל-26/7/2026
CWE
CWE-306

מוצרים מושפעים

erlang: erlang\/otp; cisco: confd basic; cisco: network services orchestrator; cisco: cloud native broadband network gateway; cisco: inode manager; cisco: smart phy; cisco: ultra packet core; cisco: ultra services platform; cisco: staros; cisco: optical site manager; cisco: ncs 1001; cisco: ncs 1002; cisco: ncs 1004; cisco: ncs 2000 shelf virtualization orchestrator firmware; cisco: ncs 2000 shelf virtualization orchestrator module

קישורים