Network Management

Why SolarWinds ARM and SolarWinds Observability Self-Hosted are not affected by CVE-2025-32433

This article explains why SolarWinds Access Rights Manager (ARM) and SolarWinds Observability Self-Hosted (formerly known as HCO) are not affected by CVE-2025-32433. Both SolarWinds products use RabbitMQ, which utilizes the Erlang component, but they do not use the SSH functionality, which is a prerequisite for the vulnerability to be exploited.

First published date

4/22/2025 3:37 PM

Last published date

7/3/2025 4:49 AM

Overview

In 2025, the National Institute of Standards and Technology (NIST) published a security bulletin about CVE-2025-32433.

CVE-2025-32433 is an unauthenticated remote code execution vulnerability affecting the SSH functionality of Erlang. 

A serious vulnerability has been identified in the Erlang/OTP SSH server that may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials.

The vulnerability described in this CVE affects numerous software companies, but it does not impact SolarWinds Access Rights Manager (ARM) and/or SolarWinds Observability Self-Hosted.

 

For additional information on the Erlang security advisory, see erlang/otp security advisory.

Product section

Orion Platform

Cause

CVE-2025-32433

Resolution

This vulnerability affects only applications that meet all the prerequisites mentioned above.