
æè¿ãErlang/OTP SSHãµãŒããŒã«æ·±å»ãªãªã¢ãŒãã³ãŒãå®è¡ïŒRCEïŒã®è匱æ§ãçºèŠãããŸããã CVE-2025-32433 ãšããŠç»é²ãããè匱æ§ã¯ãSSHã®äºåèªèšŒã¡ãã»ãŒãžãäžé©åã«åŠçããããšããå§ãŸããæ»æè ãèªèšŒãªãã§ä»»æã®ã³ãŒããå®è¡ã§ããè åšçãªã»ãã¥ãªãã£æ¬ é¥ã§ããç¹ã«ãErlang/OTPã¯éä¿¡äºæ¥è ãIoTãOTïŒéå¶æè¡ïŒãªã©ã®éèŠã€ã³ãã©ã«åºã掻çšãããŠãããå€§èŠæš¡ãªè¢«å®³ã®å¯èœæ§ãæèµ·ãããŠããŸããæ¬èšäºã§ã¯ãCVE-2025-32433ã«é¢ããè©³çŽ°ãæŽçããCriminal IPã®ITè³ç£æ€çŽ¢ãæŽ»çšããŠã€ã³ã¿ãŒãããäžã«å ¬éãããErlang/OTP SSHãµãŒããŒã®ç¹å®æ¹æ³ãšå¯Ÿå¿çãã玹ä»ããŸãã
CVE-2025-32433 : èªèšŒãªãã®SSHãããã³ã«ã®è匱æ§
ä»åã®è匱æ§ã¯ãErlang/OTP SSHããŒã¢ã³ãç¹å®ã®äºåèªèšŒã¡ãã»ãŒãžãé©åã«æ€èšŒããã«åŠçããããšããçºçããŸããããã«ãããæ»æè ã¯æªæçã«æ§æããããããã³ã«ã¡ãã»ãŒãžãéä¿¡ããããšã§ãSSHããŒã¢ã³ã®æš©éïŒäž»ã«rootæš©éïŒãéããŠã³ãã³ããå®è¡ã§ããããã«ãªããŸãã
圱é¿ãåããããŒãžã§ã³
以äžã®ããŒãžã§ã³æªæºã®Erlang/OTPç°å¢ã¯ãã¹ãŠåœ±é¿ãåããŸããå ¬åŒããããé©çšãããããŒãžã§ã³ã¯ä»¥äžã®éãã§ãã
- OTP-27.3.3以äž
- OTP-26.2.5.11以äž
- OTP-25.3.2.2.20以äž
ç¹ã«OTP-27.3.2ãOTP-26.2.5.10ãOTP-25.3.2.2.19以åã®ããŒãžã§ã³ã¯çŽæ¥åœ±é¿ãåãããããè¿ éãªã¢ããããŒããå¿ èŠã§ãã
æ»æã·ããªãªãšè åš

ãã®è匱æ§ã¯ãã§ã«Horizon3 Attack Teamã«ãã£ãŠåçŸãããŠããã2025幎4æ17æ¥ã«PoCïŒæŠå¿µå®èšŒïŒã³ãŒããPastebinã«å ¬éãããŸããã
å®éã®æ»æã¯æ¬¡ã®ãããªæ¹æ³ã§è¡ãããå¯èœæ§ããããŸãã
- æ»æè ã¯èªèšŒãªãã§SSHæ¥ç¶ã詊ã¿ã
- SSHã®äºåèªèšŒã¡ãã»ãŒãžãæ¹ããããŠéä¿¡ãã
- è匱æ§ãæå¹ãªå Žåãrootæš©éã§ä»»æã®ã³ãã³ããå®è¡ãã
- ã·ã¹ãã ææ¡ãããŒã¿æŒæŽ©ãã©ã³ãµã ãŠã§ã¢ã®é åžãå¯èœã«ãªã
Criminal IPã®ITè³ç£æ€çŽ¢ãæŽ»çšããå ¬éãµãŒããŒã®æ€åº
ã€ã³ã¿ãŒãããã«å ¬éãããErlang/OTP SSHãµãŒããŒã¯ãCriminal IPã®ITè³ç£æ€çŽ¢ãéããŠçŽ æ©ãç¹å®ã§ããŸãã
以äžã®ã¯ãšãªãçšããŠãCVE-2025-32433ã®è åšã«ãããããå¯èœæ§ã®ãããµãŒããŒã广çã«æ¢çŽ¢ããããšãã§ããæ€çŽ¢çµæãéããŠå ¬éããããµãŒããŒã®æ°ãå°åååžãè匱æ§ã®å±¥æŽãªã©æ§ã ãªæ å ±ãèŠèŠçã«ç¢ºèªããããšãã§ããŸãã
Criminal IPã®æ€çŽ¢ã¯ãšãªïŒâSSH-2.0-Erlangâ

2025幎4æ24æ¥ãåºæºã«ãåœã¯ãšãªã䜿çšããŠç¢ºèªããçµæãåèš122ä»¶ã®å ¬éäžã®Erlang/OTP SSHãµãŒããŒãæ€åºãããŸããããã®äžã«ã¯ããã§ã«è匱ãªç¶æ ã§å€æ°ã®CVEã«åœ±é¿ãããŠããè³ç£ãå€ãå«ãŸããŠããŸããã

ããIPã¢ãã¬ã¹ãã¯ãªãã¯ãããšããã®è³ç£ã®ãããŒã¯Erlang/OTPããŒã¹ã®SSHããŒã¢ã³ãå®è¡äžã§ããããšãæç¢ºã«ç€ºããŠãããã€ãŸããããã¯çŸåšCVE-2025-32433ã®åœ±é¿ãåããããªãæ§é ã§ããããšãæå³ããŸãããã®IPã¢ãã¬ã¹ã¯ã5ã€ã®ãªãŒãã³ããŒããçºèŠãããŠããããªã©ã³ãã®ã¢ã ã¹ãã«ãã ã«äœçœ®ããŠããŸãããæ€åºãããè匱æ§ã37åã§ããã®ãã¡Exploti DBããŒã¹ã®è匱æ§ã9å確èªãããŸããã
ããã¯ãåäžã®IPäžã§è匱ãªããŒãžã§ã³ã®SSHãµãŒãã¹ã皌åäžã§ããã倿°ã®é«ãªã¹ã¯ã®è匱æ§ãååšããç°å¢ãã€ã³ã¿ãŒãããã«å
¬éãããŠããããšã瀺ã代衚çãªäºäŸã§ãã
ç¹ã«ãErlang/OTPããŒã¹ã®SSHãµãŒããŒã«è匱æ§ãæ€åºãããå Žåãrootæš©éã®å¥ªåãããã¯ãã¢ã®èšçœ®ã«ã€ãªããå¯èœæ§ããããããè¿
éãªå¯Ÿå¿ãå¿
èŠã§ãã
ç·©åããã³å¯Ÿå¿ç
Erlang/OTP SSHã䜿çšããŠããçµç¹ã¯ã以äžã®å¯Ÿå¿çãçŽã¡ã«å®æœããå¿ èŠããããŸãã
- ã»ãã¥ãªãã£ãããã®é©çšïŒOTP-27.3.3ã»26.2.5.11ã»25.3.2.2.20以äžã«ã¢ããããŒããã
- SSHããŒããžã®ã¢ã¯ã»ã¹å¶éïŒãã¡ã€ã¢ãŠã©ãŒã«ãä»ããŠå€éšã¢ã¯ã»ã¹ããããã¯ãã
- SSHã®ç¡å¹åïŒSSHæ©èœãäžèŠãªå Žåãå®å šã«ç¡å¹åãã
- IPãã¯ã€ããªã¹ãã®èšå®ïŒä¿¡é ŒãããIPã¢ãã¬ã¹ã®ã¿ã¢ã¯ã»ã¹ãèš±å¯ãã
- ãã°ãšãã©ãã£ãã¯ã®ç£èŠïŒç°åžžãªSSHãžã®ã¢ã¯ã»ã¹è©Šã¿ããªã¢ã«ã¿ã€ã ã§æ€ç¥ãã
FAQïŒãããã質åïŒ
Q1. CVE-2025-32433 ã¯ã©ã®ãããªç°å¢ã§åœ±é¿ãäžããŸããïŒ
Erlang/OTPã®SSHãµãŒããŒã³ã³ããŒãã³ããå®è¡ãããã¹ãŠã®ç°å¢ã§åœ±é¿ãäžããç¹ã«ãåºæ¬çã«rootæš©éã§ããŒã¢ã³ãå®è¡ãããç°å¢ãå±éºã§ãã
Q2. CVE-2025-32433 ã«å¯Ÿããäžæçãªå¯Ÿå¿çããããŸããïŒ
ãããã®é©çšãé£ããå ŽåãSSHããŒãããããã¯ããããErlang/OTP SSHæ©èœãç¡å¹ã«ããããã¢ã¯ã»ã¹å¯èœãªIPãå¶éããæ¹æ³ã§è¢«å®³ãæå°éã«æããããšãã§ããŸãã
çµè«
CVE-2025-32433ã¯ãPoCãŸã§å ¬éãããé«ãªã¹ã¯ã®RCEè匱æ§ã§ããã峿ã®å¯Ÿå¿ãæ±ããããŸããç¹ã«ãErlang/OTPã䜿çšãããéçšã€ã³ãã©ã§ã¯ãã·ã¹ãã ææ¡ããã«ãŠã§ã¢ã®æ¡æ£ãªã©ã«ã€ãªããå¯èœæ§ãé«ããªããŸãã
Criminal IPã®ITè³ç£æ€çŽ¢ãæŽ»çšããããšã§ãã€ã³ã¿ãŒãããäžã«å ¬éãããè³ç£ãè¿ éã«ç¹å®ããçµç¹ã®ãµã€ããŒæ»æå¯Ÿè±¡é åãæå°éã«æããããã®å®è³ªçãªæ¯æŽãåŸãããšãã§ããŸãã
é¢é£ããŠIvanti VPNèåŒ±æ§ ãCVE-2025-22457ãã®å¯Ÿå¿æŠç¥ïŒCTIããŒã¹æ»æå¯Ÿè±¡é åã®æ€ç¥ããåç §ãã ããã
ããŒã¿æäŸïŒCriminal IPïŒhttps://www.criminalip.io/jaïŒãXïŒhttps://x.com/Horizon3AttackïŒãCyberWireïŒhttps://thecyberwire.com/podcasts/daily-podcast/2290/notesïŒãGBHackersïŒhttps://gbhackers.com/poc-released-for-erlang-otp-ssh-rce-vulnerability/ïŒ
ãåç §ïŒ
