A critical vulnerability has been discovered in the Erlang/OTP SSH server component, a technology widely used in telecommunications infrastructure, distributed systems, and real-time platforms. The flaw has been assigned a CVSS score of 10, reflecting both the ease of exploitation and the severe impact it can have on affected installations.
| Date | 2025-04-21 12:48:15 |
| Information |
|
Technical Summary
The issue lies in how the built-in Erlang/OTP SSH daemon processes certain protocol messages before completing the authentication handshake. By sending specially crafted SSH_MSG_CHANNEL_OPEN and SSH_MSG_CHANNEL_REQUEST packets immediately after establishing a TCP connection, an unauthenticated user can trigger the execution of arbitrary Erlang code on the server.
Key technical points:
Pre-authentication channel handling: The SSH server incorrectly accepts and processes channel-related messages before verifying user credentials.
Remote Code Execution: Malicious payloads can invoke any Erlang function, such as writing to the filesystem or launching shell processes.
Total compromise: The exploit does not require a valid user account or session state, allowing for complete system compromise, data theft, or lateral movement.
Recommendations
- Immediate Update
- Erlang/OTP 27 users: update to OTP‑27.3.3
- Erlang/OTP 26 users: update to OTP‑26.2.5.11
- Erlang/OTP 25 users: update to OTP‑25.3.2.20
- Temporary Mitigation
- Disable the Erlang SSH server component if not required.
- Otherwise, restrict access via firewall rules to trusted IPs or VPN networks only.
- Strengthen Network Perimeter
- Apply SSH access controls at the network level (e.g., host-based firewalls, security groups).
- Monitor for unexpected pre-authentication channel packets in IDS/IPS systems.
- Enhance Monitoring and Auditing
- Enable SSH logging in verbose mode to capture early channel openings and exec requests.
- Trigger alerts on anomalous or premature SSH traffic patterns.
Protect your organisation with Threat Intelligence and Digital Risk Protection.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
