U.S. CISA adds RoundCube Webmail and Erlang Erlang/OTP SSH server flaws to its Known Exploited Vulnerabilities catalog


U.S. CISA adds RoundCube Webmail and Erlang Erlang/OTP SSH server flaws to its Known Exploited Vulnerabilities catalog

Pierluigi Paganini
June 10, 2025

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds RoundCube Webmail and Erlang Erlang/OTP SSH server flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added RoundCube Webmail and Erlang Erlang/OTP SSH server flaws to its Known Exploited Vulnerabilities (KEV) catalog.

Below are the descriptions for these flaws:

  • CVE-2025-32433 (CVSS score of 10) Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability 
  • CVE-2024-42009 (CVSS score of 9.3) RoundCube Webmail Cross-Site Scripting Vulnerability 

The CVE-2025-32433 flaw is a critical issue that impacts older versions of Erlang/OTP, a toolkit used with the Erlang programming language. If you’re running a version before OTP-27.3.3, OTP-26.2.5.11, or OTP-25.3.2.20, your system could be vulnerable to remote code execution (RCE) through its built-in SSH server. This means an attacker could potentially run code on target system without logging in or needing any credentials. The issue has been fixed in the mentioned versions. Until you can update, a quick fix is to either turn off the SSH server or block access using a firewall.

Sonar’s Vulnerability Research Team discovered the CVE-2024-42009 flaw in the Roundcube webmail software in August 2024.

The issue is a critical Cross-Site Scripting (XSS) vulnerability, the researchers pointed out that Roundcube is included by default in the server hosting panel cPanel, which has millions of installations worldwide.

An attacker can trigger the vulnerability to execute arbitrary JavaScript in the victim’s browser when they view a malicious email, potentially leading to the theft of emails, contacts, passwords, and unauthorized email sending.

Sonar explained that government employees’ emails are a valuable target for APT groups carrying out cyber espionage campaigns. In October 2023, ESET Research revealed that a similar vulnerability was exploited by the APT group Winter Vivern to target European government entities.

No user interaction is required to successfully exploit the vulnerability CVE-2024-42009.

“These allow an unauthenticated attacker to steal emails and contacts, as well as send emails from a victim’s account. All the victim user has to do is view a malicious email in Roundcube.” reads the report published by Sonar. “Attackers can gain a persistent foothold in the victim’s browser across restarts, allowing them to exfiltrate emails continuously or steal the victim’s password the next time it is entered.”

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerabilities by June 30, 2025.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)







Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews



In the trailer for Mission: Impossible — The Final Reckoning, Tom Cruise as Ethan Hunt asks someone to trust him one last time. Judging by the first reactions on social media, Cruise is now asking the audience to trust him that he still delivered an action spectacle.

The social media embargo lifted for Mission: Impossible — The Final Reckoning on May 12. The initial reactions are mixed, which comes as a surprise considering how much praise the last few entries have received.

Erik Davis of Fandango and Rotten Tomatoes said Cruise takes The Final Reckoning to the next level. “It’s the biggest, wildest, and most consequential Mission movie yet,” Davis wrote on X.

Good Day’s Chicago Jake Hamilton called the plane sequence “one of cinema’s greatest stunts.” Hamilton wrote, “Mission: Impossible — The Final Reckoning is a love letter to fans who just rewatched the entire series.”

MISSION: IMPOSSIBLE – THE FINAL RECKONING is a love letter to fans who just rewatched the entire series.

It ties the entire series together as one story rather than 8 entries.

First time I’ve cried in the series.

Plane sequence is one of cinema’s greatest stunts.

I loved it. pic.twitter.com/3HxWtsY3HY

— Jake Hamilton (@JakesTakes) May 13, 2025

Indiewire’s David Ehrlich had a more negative reaction, calling it “dull and dysfunctional.” Despite praising the set pieces, Ehrlich was ultimately disappointed by The Final Reckoning, calling it a “massive heartbreaker.”

Mission: Impossible — The Final Reckoning is dull and dysfunctional in a way i didn’t think this franchise was capable of. setpieces are obviously incredible, but as someone so supportive of Cruise’s crusade to save the movies and whatnot this was a massive heartbreaker.

— david ehrlich (@davidehrlich) May 13, 2025

Griffin Schiller compared Final Reckoning to The Rise of Skywalker, saying it “plays like an egregious franchise greatest hits.”

While not as bad as TROS, FINAL RECKONING is undoubtedly cut from the same cloth. Plagued by insecurity, MISSION: IMPOSSIBLE 8 plays like an egregious franchise greatest hits. Scenes have no beginning or end, it’s scatterbrained nonsense – a constant flow of exposition &… pic.twitter.com/uCOclGGAsl

— Griffin Schiller (@griffschiller) May 13, 2025

Mission: Impossible is the gold standard for action franchises, so it’s disappointing to read about the mixed reactions. Cruise’s action sequences, including the death-defying plane stunt, will certainly be a highlight. However, the conflicting reception is not ideal, especially for a franchise that might have to disappear for the foreseeable future before Cruise returns or another actor steps in as the new lead.

Cruise headlines The Final Reckoning as Ethan Hun, the IMF agent who must race to find the Entity and destroy it before it gets into the wrong hands. The ensemble includes Hayley Atwell, Ving Rhames, Simon Pegg, Esai Morales, Pom Klementieff, Henry Czerny, Mariela Garriga, Holt McCallany, Janet McTeer, Nick Offerman, Hannah Waddingham, Tramell Tillman, Shea Whigham, Greg Tarzan Davis, Charles Parnell, Mark Gatiss, Rolf Saxon, Lucy Tulugarjuk and Angela Bassett.

Christopher McQuarrie directs from a screenplay he co-wrote with Erik Jendresen.

Mission: Impossible — The Final Reckoning opens in theaters on May 23.








Source link