NI Advisory on Erlang SSH Vulnerability

Overview

A critical vulnerability has been identified in the Erlang/OTP SSH server that may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials.  This vulnerability is identified as CVE-2025-32433

 

NI software that includes Erlang/OTP is not affected by this vulnerability since it does not enable or use SSH.

Contents

Mitigation Guidance

None.

Affected Products

NI products are not affected by this vulnerability.

CVSS Score

CVE-2025-32433 – 10.0 - CVSS:3.1 AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Further Information

At NI, we view the security of our products as an important part of our commitment to our customers.  Go to ni.com/security to stay informed and act upon security alerts and issues.

Additional Resources

Was this information helpful?

Yes

No