Page 1 of 1

Critical Erlang/OTP SSH Vulnerability (CVSS 10.0) Allows Unauthenticated Code Execution

Posted: Fri Apr 18, 2025 4:58 am
by Shane1145
A critical security vulnerability has been disclosed in the Erlang/Open Telecom Platform (OTP) SSH implementation that could permit an attacker to execute arbitrary code sans any authentication under certain conditions.

The vulnerability, tracked as CVE-2025-32433, has been given the maximum CVSS score of 10.0.

"The vulnerability allows an attacker with network access to an Erlang/OTP SSH server to execute arbitrary code without prior authentication," Ruhr University Bochum researchers Fabian Bäumer, Marcus Brinkmann, Marcel Maehren, and Jörg Schwenk said.


https://thehackernews.com/2025/04/criti ... ility.html