Threat Advisories:
Highlights of Our CISO Dinner
Upgrading struggling vulnerability management programs to Threat Exposure Management, with Host, CISO Al Lindseth formerly from Plains All American Pipeline and PWC - 6 minute podcast
0:00
0:00
👥 Play Count: Loading...

Erlang/OTP SSH Flaw Lets Hackers Bypass Login and Run Code

Red | Vulnerability Report
Download PDF
CVE-2025-32433 is a critical unauthenticated remote code execution vulnerability in the Erlang/OTP SSH server, rated CVSS 10.0 for its maximum severity. It allows attackers to execute arbitrary commands without valid credentials by exploiting improper handling of SSH messages before authentication. The bug is already being exploited in the wild, targeting OT networks and sectors like education, healthcare, and telecom, with proof-of-concept code publicly available. Users should patch immediately or restrict SSH access to mitigate risk.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox