Network Management
Why SolarWinds ARM and SolarWinds Observability Self-Hosted are not affected by CVE-2025-32433
This article explains why SolarWinds Access Rights Manager (ARM) and SolarWinds Observability Self-Hosted (formerly known as HCO) are not affected by CVE-2025-32433. Both SolarWinds products use RabbitMQ, which utilizes the Erlang component, but they do not use the SSH functionality, which is a prerequisite for the vulnerability to be exploited.
First published date
Last published date
Overview
In 2025, the National Institute of Standards and Technology (NIST) published a security bulletin about CVE-2025-32433.
CVE-2025-32433 is an unauthenticated remote code execution vulnerability affecting the SSH functionality of Erlang.
A serious vulnerability has been identified in the Erlang/OTP SSH server that may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials.
The vulnerability described in this CVE affects numerous software companies, but it does not impact SolarWinds Access Rights Manager (ARM) and/or SolarWinds Observability Self-Hosted.
For additional information on the Erlang security advisory, see erlang/otp security advisory.
Product section
Cause
CVE-2025-32433
Resolution
This vulnerability affects only applications that meet all the prerequisites mentioned above.