HomeCyber SecurityCrucial Erlang/OTP SSH Vulnerability (CVSS 10.0) Permits Unauthenticated Code Execution

Crucial Erlang/OTP SSH Vulnerability (CVSS 10.0) Permits Unauthenticated Code Execution


Apr 17, 2025Ravie LakshmananVulnerability / Community Safety

Crucial Erlang/OTP SSH Vulnerability (CVSS 10.0) Permits Unauthenticated Code Execution

A important safety vulnerability has been disclosed within the Erlang/Open Telecom Platform (OTP) SSH implementation that would allow an attacker to execute arbitrary code sans any authentication underneath sure situations.

The vulnerability, tracked as CVE-2025-32433, has been given the utmost CVSS rating of 10.0.

“The vulnerability permits an attacker with community entry to an Erlang/OTP SSH server to execute arbitrary code with out prior authentication,” Ruhr College Bochum researchers Fabian Bäumer, Marcus Brinkmann, Marcel Maehren, and Jörg Schwenk mentioned.

Cybersecurity

The difficulty stems from improper dealing with of SSH protocol messages that basically allow an attacker to ship connection protocol messages previous to authentication. Profitable exploitation of the shortcomings may end in arbitrary code execution within the context of the SSH daemon.

Additional exacerbating the danger, if the daemon course of is working as root, it allows the attacker to have full management of the machine, in flip, paving the best way for unauthorized entry to and manipulation of delicate knowledge or denial-of-service (DoS).

All customers working an SSH server based mostly on the Erlang/OTP SSH library are seemingly affected by CVE-2025-32433. It is advisable to replace to variations OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. As momentary workarounds, entry to susceptible SSH servers will be prevented utilizing applicable firewall guidelines.

In an announcement shared with The Hacker Information, Mayuresh Dani, supervisor of safety analysis at Qualys, described the vulnerability as extraordinarily important and that it will possibly permit a risk actor to carry out actions akin to putting in ransomware or siphoning off delicate knowledge.

Cybersecurity

“Erlang is regularly discovered put in on high-availability programs resulting from its sturdy and concurrent processing assist,” Dani mentioned. “A majority of Cisco and Ericsson gadgets run Erlang.”

“Any service utilizing Erlang/OTP’s SSH library for distant entry akin to these utilized in OT/IoT gadgets, edge computing gadgets are vulnerable to exploitation. Upgrading to the mounted Erlang/OTP or vendor-supported variations will remediate the vulnerability. Ought to organizations want extra time to put in upgrades, they need to prohibit SSH port entry to licensed customers alone.”

Discovered this text fascinating? Observe us on Twitter and LinkedIn to learn extra unique content material we put up.



RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -
Google search engine

Most Popular

Recent Comments