Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - OT Security - Erlang/OTP SSH Flaw Actively Exploited in OT Networks
OT Security Attacks Latest News News & Analysis Security Threats and Vulnerabilities

Erlang/OTP SSH Flaw Actively Exploited in OT Networks

Kirsten DoyleBy Kirsten DoyleAugust 13, 20253 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
OTP SSH Flaw
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

A critical flaw in Erlang’s Open Telecom Platform is under active attack. CVE-2025-32433 carries a CVSS score of 10.0 and allows remote code execution without authentication.

According to Palo Alto’s Unit 42 reseachers, it affects the platform’s native SSH daemon, used to manage hosts in telecom, 5G, and industrial systems. 

Bad actors can send specific SSH protocol messages to open ports and gain control before authentication completes. A patch is available in OTP versions 27.3.3, 26.2.5.11, and 25.3.2.20. Until updated, administrators are advised to disable the SSH service or restrict access to trusted sources.

From May 1 to May 9, exploitation attempts rose sharply. Nearly three-quarters (75%) of detections came from firewalls in operational technology networks. Many vulnerable services were exposed on industrial ports, including TCP 2222, which is also used in automation protocols.

Healthcare, agriculture, media, entertainment, and high technology saw the highest OT impact. Education networks recorded the greatest overall number of attempts. In Japan, almost every detection came from OT environments. The United States saw the highest volume, with more than 1,900 OT-related signatures.

Two Main Payloads

Two main payload types have been observed. One opens a TCP connection bound to a shell for interactive commands. The other creates a reverse shell to a remote host on port 6667, often linked to botnet control.

Several payloads triggered DNS lookups to random subdomains under dns.outbound.watchtowr[.]com, a sign of out-of-band execution testing designed to avoid direct feedback.

Researchers note that exploitation comes in bursts. Peak activity days often match spikes in OT-specific triggers. This pattern complicates detection and suggests deliberate, targeted campaigns.

Almost 60% of all firewalls detecting attempts were in OT networks. These devices saw 160% more attempts per firewall than their IT counterparts. Exposure in education, healthcare, and high technology shows that OT risk is no longer confined to factories or utilities. 

The convergence of IT and OT, combined with exposed industrial ports, has widened the attack surface.

Administrators should patch immediately, update intrusion prevention signatures, and enforce strict network segmentation.

This vulnerability shows how a flaw in a general-purpose software component can become an operational threat overnight. When attackers find a way into an operational network, they do not hesitate.

Disproportionately Affecting OT

April Lenhard, Principal Product Manager at Qualys, says the real danger with CVE-2025-32433 is that it’s not just an IT vulnerability: it is disproportionately affecting operational technology (OT) networks, and it’s already actively showing up in systems tied to critical infrastructure.

“Most known compromises involve OT assets that control physical processes like robotics, pumps, valves, or even safety systems. Exploitation could alter sensor readings, trigger outages, introduce safety risks, and cause physical damage,” Lenhard adds. 

“By the time breaches are detected, attackers were often already inside the network through other means and simply moving laterally toward OT systems: this means they are exploiting the growing convergence of IT and OT systems to penetrate critical infrastructure across industries.”

Severe Consequences

Thomas Richards, Infrastructure Security Practice Director at Black Duck, adds that this vulnerability, if exploited, could have severe consequences for the organization, its network, and its operations.

“The attacker would have full control over the system which can result in a compromise of sensitive information and allow them to compromise additional hosts within the network. It would also allow an attacker to disrupt the operations of any connected systems.  This is additionally concerning for any critical infrastructure as the disruption could negatively impact large portions of the population.” 

He says addressing this vulnerability should be a top priority for any security team responsible for an OT network.  

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals
  • Kirsten Doyle
    ShinyHunters targets Oracle PeopleSoft customers through critical zero-day
  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

CISOs Take Charge as OT Security Matures

July 16, 20254 Mins Read

2.8M UK Businesses Vulnerable To IoT And OT Cyber-Attacks

February 21, 20194 Mins Read

ADIPEC 2018: Skybox Calls On Oil And Gas Companies To Unify IT And OT Cybersecurity

November 12, 20182 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}