Erlang/OTP 17.0 < 27.3.4.15 / 28.0 < 28.5.0.4 / 29.0 < 29.0.4 Multiple Vulnerabilities

high Nessus Plugin ID 331349

Synopsis

The remote host is missing a security update.

Description

The version of Erlang/OTP installed on the remote host is 17.0 prior to 27.3.4.15, 28.0 prior to 28.5.0.4, or 29.0 prior to 29.0.4. It is, therefore, affected by multiple vulnerabilities:

- The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in ServerHello was among the suites offered by the client in ClientHello.
An on-path attacker can respond with a ServerHello selecting an anonymous key exchange suite, bypassing certificate validation and allowing interception of traffic. (CVE-2026-55953)

- Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corrupt the driver's memory by sending a single text-encoded H.248/Megaco message containing an oversized property parm name. (CVE-2026-59250)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Erlang/OTP version 27.3.4.15, 28.5.0.4, or 29.0.4 or later.

See Also

https://github.com/erlang/otp/security/advisories/GHSA-7xgh-gmgf-q2g7

https://github.com/erlang/otp/security/advisories/GHSA-c6cw-pr89-w882

Plugin Details

Severity: High

ID: 331349

File Name: erlang_otp_CVE-2026-55953.nasl

Version: 1.1

Type: Local

Agent: windows, macosx, unix

Family: Misc.

Published: 7/31/2026

Updated: 7/31/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.3

Percentile: 96.67

CVSS v2

Risk Factor: Medium

Base Score: 5.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:N

CVSS Score Source: CVE-2026-55953

CVSS v3

Risk Factor: High

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS Score Source: CVE-2026-59250

Vulnerability Information

CPE: cpe:/a:erlang:erlang%2fotp

Required KB Items: installed_sw/Erlang-OTP

Patch Publication Date: 7/27/2026

Vulnerability Publication Date: 7/27/2026

Reference Information

CVE: CVE-2026-55953, CVE-2026-59250