Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.
2025-04-16T22:15:14.373
2025-06-12T16:05:19.650
Analyzed
CVSSv3.1: 10.0 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | erlang | erlang\/otp | < 25.3.2.20 | Yes |
Application | erlang | erlang\/otp | < 26.2.5.11 | Yes |
Application | erlang | erlang\/otp | < 27.3.3 | Yes |
Application | cisco | confd_basic | < 7.7.19.1 | Yes |
Application | cisco | confd_basic | < 8.1.16.2 | Yes |
Application | cisco | confd_basic | < 8.2.11.1 | Yes |
Application | cisco | confd_basic | < 8.3.8.1 | Yes |
Application | cisco | confd_basic | < 8.4.4.1 | Yes |
Application | cisco | network_services_orchestrator | < 5.7.19.1 | Yes |
Application | cisco | network_services_orchestrator | < 6.1.16.2 | Yes |
Application | cisco | network_services_orchestrator | < 6.2.11.1 | Yes |
Application | cisco | network_services_orchestrator | < 6.3.8.1 | Yes |
Application | cisco | network_services_orchestrator | < 6.4.1.1 | Yes |
Application | cisco | network_services_orchestrator | < 6.4.4.1 | Yes |
Application | cisco | cloud_native_broadband_network_gateway | < 2025.03.1 | Yes |
Application | cisco | inode_manager | - | Yes |
Application | cisco | smart_phy | < 25.2 | Yes |
Application | cisco | ultra_packet_core | - | Yes |
Application | cisco | ultra_services_platform | - | Yes |
Operating System | cisco | staros | * | Yes |
Application | cisco | optical_site_manager | < 25.2.1 | Yes |
Hardware | cisco | ncs_1001 | - | No |
Hardware | cisco | ncs_1002 | - | No |
Hardware | cisco | ncs_1004 | - | No |
Operating System | cisco | ncs_2000_shelf_virtualization_orchestrator_firmware | < 25.1.1 | Yes |
Hardware | cisco | ncs_2000_shelf_virtualization_orchestrator_module | - | No |
Application | cisco | enterprise_nfv_infrastructure_software | < 4.18 | Yes |
Application | cisco | ultra_cloud_core | < 2025.03.1 | Yes |
Operating System | cisco | rv160w_firmware | - | Yes |
Hardware | cisco | rv160w | - | No |
Operating System | cisco | rv260_firmware | - | Yes |
Hardware | cisco | rv260 | - | No |
Operating System | cisco | rv160_firmware | - | Yes |
Hardware | cisco | rv160 | - | No |
Operating System | cisco | rv260p_firmware | - | Yes |
Hardware | cisco | rv260p | - | No |
Operating System | cisco | rv260w_firmware | - | Yes |
Hardware | cisco | rv260w | - | No |
Operating System | cisco | rv340_firmware | - | Yes |
Hardware | cisco | rv340 | - | No |
Operating System | cisco | rv340w_firmware | - | Yes |
Hardware | cisco | rv340w | - | No |
Operating System | cisco | rv345_firmware | - | Yes |
Hardware | cisco | rv345 | - | No |
Operating System | cisco | rv345p_firmware | - | Yes |
Hardware | cisco | rv345p | - | No |